Rail Maze Puzzle
nelbpdjegmhhgpfcjclhdmkcglimkjpp
Risk Score
4.29
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy hosted on third-party CDN (cloudapi.stream), not scoped to this extension, admits data collection with no retention disclosure.
- Uninstall URL hijack and install URL hijack flags set — extension intercepts install/uninstall lifecycle events.
- eval() of dynamic variable in opus.wasm.js — code execution risk in sandbox context.
- innerHTML assigned from navigator.userAgent — DOM-XSS sink with no CSP guard on sandbox (unsafe-eval/unsafe-inline present).
- Free-webmail developer with no developer name, 7 installs — minimal accountability and throwaway profile.
Evidence
- uninstall_url_hijack manifest Extension sets an uninstall URL hook; target null but hook is present — lifecycle hijack signal.
- install_url_hijack manifest onInstalled opens popup/index.html — low severity internal target but install hijack flag is set.
- privacy_policy_mismatch store Policy at cdn.cloudapi.stream: fetched=true, scope_extension=false, data_collection=true, retention=false — generic CDN-hosted policy.
- eval_user_input crx opus.wasm.js uses eval(funcstr) — dynamic code execution in sandbox with unsafe-eval allowed.
- dom_sink_innerhtml_userctrl crx supportcheck.js assigns navigator.userAgent into innerHTML — DOM-XSS sink; sandbox has unsafe-inline.
- sandbox_csp_unsafe manifest Sandbox CSP allows unsafe-eval and unsafe-inline on script-src, amplifying eval and innerHTML risks.
- free_webmail_no_dev_name store Developer is viktornadiezhdin@gmail.com with no developer_name — free webmail, no business accountability.
- webstore_uninstall_hijack_pattern store Webstore +3.0 for uninstall URL hijack signal per rubric (Pillar 3).
Pillar Scores
Permissions0.00
Reputation5.50
Network0.00
Webstore5.00
Maintenance3.50
Privacy10.00
Code Quality5.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 08:30
Listing SHA
8c04e21dcf70…
Force block
— not fired
Score recovered
no
Elapsed
—