Doodle Jump - Unblocked
dkpgnhhmldhhndckjklccljdddgjmgbf
Risk Score
5.47
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Uninstall and install URL hijacks detected — extension redirects on install/uninstall to undisclosed third-party URLs.
- Developer email is free Gmail with no verified identity; no developer name supplied.
- Privacy policy scope_extension==false with data_collection+third_party_sharing admitted — generic non-scoped policy.
- Extension stale 28 months with no no-CSP penalty (MV3), but contacts external host doodlejump.net.
- Manifest localization strings hide real name/description — low transparency.
Evidence
- install_url_hijack + uninstall_url_hijack crx Both install and uninstall URL hijacks flagged; targets null (undisclosed). Classic monetization shell pattern.
- free_webmail_dev_no_name store Developer email drivemadorg@gmail.com, developer_name empty. No verified business identity.
- privacy_policy_generic api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true — admits sharing, not scoped to extension.
- maintenance_stale store Last updated April 2024, 28 months since update — falls in 24-36mo band (+8.5).
- external_host_doodlejump.net crx JS contacts doodlejump.net — external host outside developer's own domain; purpose undisclosed.
- manifest_localization_obfuscation manifest manifest_name and manifest_description are __MSG__ tokens; real content not inspectable from listing.
- install_url_hijack_pattern crx onInstalled redirect to 3rd party (+2.0 webstore). Combined with uninstall hijack: monetization shell fingerprint.
- no_csp crx csp_present=false on MV3; no v2 +2.0 penalty (MV3 strict default), but no hardening declared.
Pillar Scores
Permissions0.00
Reputation8.00
Network0.00
Webstore8.50
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 04:59
Listing SHA
c090c28c6f9d…
Force block
— not fired
Score recovered
no
Elapsed
—