Video Poker Jacks or Better
peflgkmfmoijonfgcjdlpnnfdegnlaji
Risk Score
4.09
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Uninstall and install URL hijack signals indicate monetization/tracking behavior on lifecycle events.
- Privacy policy hosted on CDN domain (cloudapi.stream), not scoped to this extension; third-party sharing admitted.
- jquery@3.2.1 bundles 3 medium-severity XSS CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023), unfixed.
- 7 external JS hosts including suspicious CDN (cloudapi.stream); sandbox CSP allows unsafe-eval and unsafe-inline.
- Free-webmail developer (gmail), no developer name, no verified publisher — low accountability.
Evidence
- install_url_hijack manifest install_url_hijack=true; target=popup/index.html — onInstalled opens internal page, pattern consistent with lifecycle tracking.
- uninstall_url_hijack manifest uninstall_url_hijack=true; target=null — setUninstallURL() called but target not captured; monetization pattern.
- privacy_policy_generic_cdn store Policy at cdn.cloudapi.stream: scope_extension=false, data_collection=false, third_party_sharing=true. Not scoped to extension.
- jquery_cves crx jquery@3.2.1 has 3 medium XSS CVEs; fixed_in=3.5.0. Library not updated.
- sandbox_csp_unsafe manifest Sandbox CSP allows unsafe-eval and unsafe-inline on script-src; elevates XSS exploitability of jquery CVEs.
- external_hosts crx 7 external JS hosts: bnjmnt4n.now.sh, cloudapi.stream, codecanyon.net, createjs.com, mths.be, codethislab.com, opensource.org.
- geo_diversity crx JS hosts span 4 countries (CA, IT, NL, US); triggers geo-diversity signal for Entertainment category.
- developer_identity store Developer email nadejdinv@gmail.com; no developer name; no verified publisher; free-webmail identity.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@3.2.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.2.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.2.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Pillar Scores
Permissions0.00
Reputation7.00
Network0.00
Webstore6.50
Maintenance1.50
Privacy9.00
Code Quality2.00
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 08:59
Listing SHA
e81a9ead7206…
Force block
— not fired
Score recovered
no
Elapsed
—