Gold of Egypt - Slot Machine
pllkanemicadpcmkfodglahcocfdgkhj
Risk Score
4.28
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy fetched from CDN (cdn.cloudapi.stream) admits data collection and third-party sharing without scoping to this extension — scores maximum privacy risk.
- No developer name listed; unverified publisher on an obscure TLD (.rodeo) with only 14 installs.
- Sandbox CSP allows unsafe-inline and unsafe-eval, enabling script execution outside strict policy.
- Privacy policy hosted on a CDN subdomain not the developer's own domain; cannot be pinned to accountability.
- Extension contacts multiple cloudapi.stream subdomains with no transparency about data flows.
Evidence
- privacy_policy_admits_collection_and_sharing_unscoped api policy fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 rule D)
- no_developer_name store developer_name is empty string; no verified publisher badge; no recognized org.
- sandbox_csp_unsafe_eval_inline manifest sandbox CSP includes unsafe-inline and unsafe-eval allowing dynamic code execution in sandboxed pages.
- privacy_policy_on_cdn_not_dev_domain store Privacy policy URL is cdn.cloudapi.stream, not top.rodeo; weakens accountability.
- low_install_count store Only 14 installs; tail-attack-surface and small-install anomalies do not trigger (no HIGH perms).
- host_permissions_cloudapi_stream manifest Two cloudapi.stream subdomains in host_permissions; third-party game backend, unverifiable.
- no_code_findings_no_obfuscation crx obfuscation_score=0.0, code_findings_raw empty, 17 JS files scanned — code quality clean.
- maintenance_6_to_12_months store months_since_update=11; falls in 6-12mo band → +3.5 maintenance.
Permissions Breakdown
- identity low OAuth identity; low risk alone, but paired with googleapis host permission enables auth flows.
- host: https://www.googleapis.com/* low Google APIs; consistent with identity permission for auth.
- host: https://wheel.cloudapi.stream/* medium Unknown third-party CDN domain (cloudapi.stream); broad access to a non-transparent host.
- host: https://mines.cloudapi.stream/* medium Second cloudapi.stream subdomain; game backend but unverifiable third-party host.
- host: https://top.rodeo/* low Developer's own domain; expected for a game extension.
Pillar Scores
Permissions1.50
Reputation6.50
Network2.00
Webstore3.00
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 08:29
Listing SHA
2b2f6df1f91f…
Force block
— not fired
Score recovered
no
Elapsed
—