Offline Games - No Wifi Games
cflakkfdifccmpjmakkjpignhgiebpkd
Risk Score
4.49
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- eval() and new Function() on user-controllable input in mario-bros game files — direct code execution risk
- Privacy policy covers monkeymart.org with data collection + third-party sharing but zero extension scope — does not describe this extension
- 4 unique medium-severity jQuery CVEs (XSS) across two bundled versions (2.0.3, 2.1.1); no CSP amplifies exploit probability
- Developer identity: no name, gmail-only, no verified business; install-open URL hijack on install
- 12 external JS hosts loaded with no CSP; no content integrity enforcement
Evidence
- eval_user_input + function_constructor crx mario-bros/ui.js uses eval(onclick+'()'); editor.js uses new Function(editor.rawfunc) — arbitrary code exec from user input.
- privacy_policy_mismatch store Policy at monkeymart.org admits data collection + third-party sharing but scope_extension=false; does not cover this extension.
- jquery_cves_no_csp crx jQuery 2.0.3 and 2.1.1 bundled with 4 unique moderate XSS CVEs (CVE-2015-9251, CVE-2019-11358, CVE-2020-11022/23); csp_present=false.
- install_url_hijack crx install_url_hijack=true; onInstalled opens a URL (target null in data). Monetization/tracking signal.
- developer_identity store No developer name, gmail-only address (cindyohio2070@gmail.com), no verified business domain.
- js_external_hosts crx 12 external hosts referenced in JS (buzz.jaysalvat.com, createjs.com, duckclicker.org, github.com, etc.) with no CSP integrity.
- script_src_dynamic crx jQuery in flappy game dynamically creates <script> elements — remote code loading path exists.
- verified_publisher_featured store Extension is verified_publisher=true and is_featured_by_google=true, partially mitigating reputation risk.
CVE Exposures (8)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@2.0.3 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@2.0.3 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@2.0.3 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@2.0.3 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
| CVE-2019-11358 | jquery@2.1.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@2.1.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@2.1.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@2.1.1 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Pillar Scores
Permissions0.00
Reputation5.50
Network2.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality7.50
CVE Exposure4.50
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:23
Listing SHA
214daacc8976…
Force block
— not fired
Score recovered
no
Elapsed
35.6s