Knife And Jems
ghjkcohniofdhplnaalopmeholomaidg
Risk Score
4.77
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Uninstall and install URL hijack both present — classic traffic-monetization pattern.
- Privacy policy URL returns connection error; cannot verify data handling disclosures.
- No developer name disclosed; manifest uses MSG placeholders hiding true identity.
- Extension stale at 24 months with external JS host (www.play.gameograf.com) still active.
- Verified publisher status cannot reduce full risk given stale age and unresolvable privacy policy.
Evidence
- install_url_hijack crx install_url_hijack=true; onInstalled opens 3rd-party URL — classic monetization shell.
- uninstall_url_hijack crx uninstall_url_hijack=true; sets uninstall redirect to 3rd-party URL.
- privacy_policy_unreachable store Privacy policy fetch failed (ConnectionError); policy cannot be evaluated — scored as no policy.
- no_developer_name store developer_name is empty; manifest name/description use MSG placeholders.
- maintenance_stale store Last updated September 2024; months_since_update=24, borderline 24-36 band.
- external_js_host crx js_external_hosts: [www.play.gameograf.com] — remote JS dependency present.
- verified_publisher store Verified publisher badge present; partial trust discount applied but capped by stale/no-policy conditions.
- empty_permissions_with_hijacks crx Zero declared permissions but both install/uninstall hijacks active — atypical for a benign game extension.
Pillar Scores
Permissions0.00
Reputation5.00
Network0.00
Webstore8.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 11:07
Listing SHA
d219520ad3e6…
Force block
— not fired
Score recovered
no
Elapsed
—