Mahjong Çevrimiçi Bağlan
oampnnmakfpmmfdhlelijkggaeiiijdi
Risk Score
6.33
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- Developer is free-webmail (gmail) with no name, no verified business — high identity opacity.
- Uninstall and install URL hijack flags present despite targets being null — suspicious instrumentation.
- Privacy policy is Google's generic account policy, not scoped to this extension; admits data collection and 3rd-party sharing.
- Extension last updated 39 months ago — deeply stale with no maintenance signal.
- External JS host yoki.games loaded; unverifiable third-party game portal with no transparency.
Evidence
- free_webmail_dev_no_name store Developer email rosiekumari5g679@gmail.com, no developer name provided — anonymous free-webmail identity.
- uninstall_install_url_hijack manifest Both uninstall_url_hijack and install_url_hijack are true; targets null but hooks are set.
- generic_google_privacy_policy store Privacy policy URL is myaccount.google.com/privacypolicy — Google's own policy, not scoped to this extension.
- privacy_policy_admits_data_sharing api Policy classification: scope_extension=false, data_collection=true, third_party_sharing=true — worst-case generic policy.
- stale_extension store Last updated May 2023, 39 months ago — exceeds 36-month staleness threshold.
- external_js_host crx js_external_hosts includes yoki.games — unverifiable third-party game portal.
- verified_publisher_claimed store verified_publisher=true but dev is free-webmail with no name; stale >18mo caps discount to -1.0 per invariant 0c.
- installs_very_low store Only 8 installs — negligible reach but signals untested/unmaintained software.
Permissions Breakdown
- storage low Stores local game state; low intrinsic risk.
- notifications low Can show notifications; medium by rubric but no host access lowers impact.
- alarms low Schedules background tasks; limited capability alone.
Pillar Scores
Permissions1.20
Reputation8.50
Network0.00
Webstore7.50
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 09:59
Listing SHA
d20a09d3d0e5…
Force block
— not fired
Score recovered
no
Elapsed
—