Farm - Slot Machine
ndajcmifndknmkckdcdefkpgcodciggk
Risk Score
4.39
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy hosted on cdn.cloudapi.stream admits data collection AND third-party sharing without extension-specific scope — worst-case Privacy score.
- No developer name listed; low install count (19) with multiple developer-controlled external hosts raises accountability concern.
- Sandbox CSP allows unsafe-inline and unsafe-eval; sandboxed content could evaluate arbitrary scripts.
- Privacy policy URL is on a CDN subdomain (cloudapi.stream), not the developer's primary domain, reducing trust and traceability.
- Extension is 11 months stale with only 19 installs; low visibility makes supply-chain takeover harder to detect.
Evidence
- privacy_policy_admits_third_party_sharing_no_scope api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → D clause: +10.0 Privacy.
- no_developer_name store developer_name is empty string; +1.0 Reputation per rubric.
- sandbox_csp_unsafe_eval_inline manifest Sandbox CSP includes unsafe-inline and unsafe-eval on script-src; extension_pages CSP is strict.
- multiple_developer_controlled_external_hosts crx wheel.cloudapi.stream, mines.cloudapi.stream, top.rodeo all contacted; 12 external JS hosts total.
- no_verified_publisher_no_featured store verified_publisher=false, is_featured_by_google=false; no trust discounts applicable.
- maintenance_6_to_12_months store months_since_update=11; +3.5 Maintenance score.
- code_quality_clean crx code_findings_raw empty, obfuscation_score=0.0; Code Quality pillar=0.0.
- cve_findings_empty crx No CVEs detected in bundled libraries; CVE pillar=0.0.
Permissions Breakdown
- identity low OAuth identity; low scope, no broad host implied alone.
- https://www.googleapis.com/* low Standard Google API endpoint; expected with identity permission.
- https://wheel.cloudapi.stream/* medium Developer-controlled CDN subdomain; opacity risk for data sent here.
- https://mines.cloudapi.stream/* medium Second developer-controlled CDN subdomain; exfil surface.
- https://top.rodeo/* low Developer's own domain; expected for a game backend.
Pillar Scores
Permissions1.30
Reputation6.50
Network2.50
Webstore3.00
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 08:55
Listing SHA
65b36ce1bd92…
Force block
— not fired
Score recovered
no
Elapsed
—