Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Offline Games - No Wifi Games

cflakkfdifccmpjmakkjpignhgiebpkd
Risk Score
4.49
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 90,000
Rating 4.5
Last updated 2026-06-15
Manifest version MV3
CSP present ❌ no
Developer cindyohio2070@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • eval() and new Function() on user-controllable input in mario-bros game files — direct code execution risk
  • Privacy policy covers monkeymart.org with data collection + third-party sharing but zero extension scope — does not describe this extension
  • 4 unique medium-severity jQuery CVEs (XSS) across two bundled versions (2.0.3, 2.1.1); no CSP amplifies exploit probability
  • Developer identity: no name, gmail-only, no verified business; install-open URL hijack on install
  • 12 external JS hosts loaded with no CSP; no content integrity enforcement

Evidence

  • eval_user_input + function_constructor crx mario-bros/ui.js uses eval(onclick+'()'); editor.js uses new Function(editor.rawfunc) — arbitrary code exec from user input.
  • privacy_policy_mismatch store Policy at monkeymart.org admits data collection + third-party sharing but scope_extension=false; does not cover this extension.
  • jquery_cves_no_csp crx jQuery 2.0.3 and 2.1.1 bundled with 4 unique moderate XSS CVEs (CVE-2015-9251, CVE-2019-11358, CVE-2020-11022/23); csp_present=false.
  • install_url_hijack crx install_url_hijack=true; onInstalled opens a URL (target null in data). Monetization/tracking signal.
  • developer_identity store No developer name, gmail-only address (cindyohio2070@gmail.com), no verified business domain.
  • js_external_hosts crx 12 external hosts referenced in JS (buzz.jaysalvat.com, createjs.com, duckclicker.org, github.com, etc.) with no CSP integrity.
  • script_src_dynamic crx jQuery in flappy game dynamically creates <script> elements — remote code loading path exists.
  • verified_publisher_featured store Extension is verified_publisher=true and is_featured_by_google=true, partially mitigating reputation risk.

CVE Exposures (8)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@2.0.3 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@2.0.3 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@2.0.3 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@2.0.3 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery
CVE-2019-11358 jquery@2.1.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@2.1.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@2.1.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@2.1.1 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Pillar Scores

Permissions0.00
Reputation5.50
Network2.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality7.50
CVE Exposure4.50

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:23
Listing SHA 214daacc8976…
Force block — not fired
Score recovered no
Elapsed 35.6s