Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Super Mario Bros Classic Game

baaekoloipdmhgffglokngoonljoachp
Risk Score
5.07
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 1,000
Rating 2.0
Last updated 2025-02-17 (18 months ago)
Manifest version MV3
CSP present ❌ no
Developer classroom6x2@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall URL hijack and install URL hijack both set — classic monetization/tracking shell pattern.
  • Privacy policy fetched but NOT scoped to this extension, admits data collection AND third-party sharing → +10.0 privacy.
  • Developer uses free-webmail (gmail) with no developer name and no verified business domain.
  • External JS host poki.ee loaded by 38 JS files with no CSP — unconstrained remote script surface.
  • Low rating (2.0), 18-month stale update, no developer name — governance and accountability gaps.

Evidence

  • uninstall_url_hijack + install_url_hijack crx Both onInstalled and uninstall URL hooks present — strong monetization/tracking shell indicator.
  • free_webmail_developer store Developer email classroom6x2@gmail.com, no developer name, no verified business domain.
  • privacy_policy_generic_data_sharing api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → D rule +10.0.
  • external_js_host_poki.ee crx 38 JS files scanned; external host poki.ee loaded with no CSP — unconstrained remote script execution.
  • no_csp_mv3 manifest content_security_policy is null; MV3 default CSP applies but no explicit CSP for extension pages.
  • stale_update_18mo store Last updated February 2025, 18 months since update → maintenance score +6.0.
  • low_rating store Rating 2.0 — below threshold but rating_count not confirmed >= 50, no multiplier applied.
  • verified_publisher_with_free_webmail store verified_publisher=true but email is gmail; no domain match to policy URL, discount capped by stale+no-resolve signals.

Pillar Scores

Permissions0.00
Reputation7.50
Network0.00
Webstore8.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 09:25
Listing SHA 40761045ceeb…
Force block — not fired
Score recovered no
Elapsed