NFT Airdrop Manager
ohalndninddkaceoghngcpcmeeboppkm
Risk Score
5.07
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and 3rd-party sharing.
- Extension last updated 25 months ago (zombie-tier staleness) with no changelog.
- innerHTML DOM-XSS sink present in bundled JS with no CSP to mitigate it.
- Contacts external host airdropmanager.xyz at runtime — unverified third-party backend for an NFT/crypto tool.
- Unverified developer on .xyz domain with no webstore badges; very low install base (188).
Evidence
- privacy_policy_generic store Policy URL is myaccount.google.com/privacypolicy — Google's own policy, not scoped to this extension; scope_extension=false, data_collection=true, third_party_sharing=true.
- stale_extension store Last updated May 2024; 25 months since update — maintenance pillar 8.5.
- dom_xss_sink_no_csp crx dom_sink_innerhtml_userctrl in assets/index.html.1679103f.js with csp_present=false elevates code quality risk.
- external_host_airdropmanager crx js_external_hosts includes airdropmanager.xyz — unverified crypto-adjacent backend; reactjs.org is benign CDN reference.
- react_16_13_1_bundled crx React 16.13.1 bundled; below 16.14 patch threshold; no CVEs found in cve_findings_raw but version is aging.
- unverified_developer store verified_publisher=false, is_featured_by_google=false; dev email on .xyz domain; no recognized org.
- low_install_crypto_niche store Only 188 installs; NFT/airdrop category is high-fraud-risk niche with minimal community vetting.
- no_csp manifest content_security_policy is null; MV3 has strict default but no explicit CSP amplifies DOM-sink risk.
Permissions Breakdown
- storage low Stores local extension state; minimal risk.
- background low Keeps service worker alive; low risk without host permissions.
- alarms low Schedules periodic tasks; low standalone risk.
Pillar Scores
Permissions0.90
Reputation5.50
Network2.00
Webstore3.50
Maintenance8.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:01
Listing SHA
bf4db19cee69…
Force block
— not fired
Score recovered
no
Elapsed
22.6s