Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Doodle Jump - Unblocked

dkpgnhhmldhhndckjklccljdddgjmgbf
Risk Score
5.47
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 750
Rating 5.0
Last updated 2024-04-15 (28 months ago)
Manifest version MV3
CSP present ❌ no
Developer drivemadorg@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall and install URL hijacks detected — extension redirects on install/uninstall to undisclosed third-party URLs.
  • Developer email is free Gmail with no verified identity; no developer name supplied.
  • Privacy policy scope_extension==false with data_collection+third_party_sharing admitted — generic non-scoped policy.
  • Extension stale 28 months with no no-CSP penalty (MV3), but contacts external host doodlejump.net.
  • Manifest localization strings hide real name/description — low transparency.

Evidence

  • install_url_hijack + uninstall_url_hijack crx Both install and uninstall URL hijacks flagged; targets null (undisclosed). Classic monetization shell pattern.
  • free_webmail_dev_no_name store Developer email drivemadorg@gmail.com, developer_name empty. No verified business identity.
  • privacy_policy_generic api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true — admits sharing, not scoped to extension.
  • maintenance_stale store Last updated April 2024, 28 months since update — falls in 24-36mo band (+8.5).
  • external_host_doodlejump.net crx JS contacts doodlejump.net — external host outside developer's own domain; purpose undisclosed.
  • manifest_localization_obfuscation manifest manifest_name and manifest_description are __MSG__ tokens; real content not inspectable from listing.
  • install_url_hijack_pattern crx onInstalled redirect to 3rd party (+2.0 webstore). Combined with uninstall hijack: monetization shell fingerprint.
  • no_csp crx csp_present=false on MV3; no v2 +2.0 penalty (MV3 strict default), but no hardening declared.

Pillar Scores

Permissions0.00
Reputation8.00
Network0.00
Webstore8.50
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 04:59
Listing SHA c090c28c6f9d…
Force block — not fired
Score recovered no
Elapsed