Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Subway Surfers Game

diapchdifbiaecllaeopdmeilljbcihp
Risk Score
4.46
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 61
Rating
Last updated 2026-05-06 (4 months ago)
Manifest version MV3
CSP present ❌ no
Developer halilseker3455@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall and install URL hijacks set with null targets — classic traffic/monetization shell pattern.
  • Privacy policy is Google's generic account policy, not scoped to this extension; admits data collection and 3rd-party sharing.
  • External JS hosted on gameograf.com (third-party game portal) — remote code loaded outside developer control.
  • Free-webmail developer (gmail) with no developer name and no business domain; identity unverifiable.
  • Manifest uses localised message placeholders (__MSG__) with zero declared permissions — minimal observable surface but unverifiable intent.

Evidence

  • uninstall_url_hijack + install_url_hijack crx Both onInstalled and uninstall URL hooks set; targets null but hooks present — monetization/traffic-redirect shell fingerprint.
  • external_js_host crx js_external_hosts: [gameograf.com] — game portal CDN; remote code not under developer control.
  • privacy_policy_generic store Policy URL is Google account privacy page; scope_extension=false, data_collection=true, third_party_sharing=true.
  • developer_identity store Gmail developer email halilseker3455@gmail.com, no developer name, no business domain; verified_publisher=true but identity weak.
  • manifest_placeholders crx manifest_name and manifest_description use __MSG__ keys — obfuscates stated purpose at review time.
  • no_permissions_declared manifest permissions[], host_permissions[], content_scripts_matches all empty; surface area hidden in JS loaded from gameograf.com.
  • low_installs_game_shell store Only 61 installs, 0 rating; Entertainment/game shell with hijack hooks and third-party JS is high-risk pattern.
  • csp_absent crx content_security_policy is null; MV3 default CSP applies but external JS host gameograf.com still loaded.

Pillar Scores

Permissions0.00
Reputation7.50
Network0.00
Webstore8.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 05:28
Listing SHA 4ed18f72035c…
Force block — not fired
Score recovered no
Elapsed