Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Pacman Game Offline for Google Chrome

ciiepdilkgkacpioofhgljmidgjodjcl
Risk Score
5.63
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 90,000
Rating 4.3
Last updated 2024-05-31 (25 months ago)
Manifest version MV3
CSP present ❌ no
Developer fugiman20@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Google brand impersonation in title by unverified gmail developer with no dev name
  • Privacy policy URL fetch failed (retrobowl.me unrelated domain) — treated as no policy
  • 4 medium-severity jQuery CVEs (v2.1.3) with no CSP, unfixed for 2+ years
  • install_url_hijack AND uninstall_url_hijack flags set; uninstall URL redirects to 3rd party
  • Extension stale 25 months; description_promise.is_shell_pattern == true

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true for 'google'; developer_email is gmail, confirmed_owner=false
  • privacy_policy_fetch_failed crx privacy_policy_classification.fetched=false (fetch_error:HTTPError); retrobowl.me is unrelated domain
  • jquery_cves crx jquery@2.1.3 has 4 moderate CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023, CVE-2015-9251); no CSP
  • install_uninstall_url_hijack crx install_url_hijack=true AND uninstall_url_hijack=true; targets null but flags are authoritative
  • shell_pattern store description_promise.is_shell_pattern=true; play_or_open promise with no substantive permissions
  • stale_extension store months_since_update=25; last_updated May 2024; 90k installs still active
  • free_webmail_no_dev_name store developer_name=''; developer_email=fugiman20@gmail.com; no business website
  • external_hosts crx js_external_hosts: raw.githubusercontent.com, www.w3technic.com — 2 distinct external JS origins

CVE Exposures (4)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@2.1.3 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@2.1.3 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@2.1.3 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@2.1.3 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Pillar Scores

Permissions0.00
Reputation7.50
Network2.00
Webstore8.50
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:23
Listing SHA f0c6a516775f…
Force block — not fired
Score recovered no
Elapsed 25.1s