Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

flappy birdie (night farm mode)

hpkfkbmcphnigepfjmapkdaedglohgjg
Risk Score
5.55
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 30,000
Rating 4.9
Last updated 2026-02-15 (6 months ago)
Manifest version MV3
CSP present ❌ no
Developer micthelldawsen7@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's own account policy — not scoped to this extension at all; admits data collection and 3rd-party sharing.
  • jquery@1.10.2 bundles 3 unpatched medium-severity XSS CVEs (unfixed); no CSP amplifies risk.
  • Content scripts injected on *://*/* give full DOM read/write access to every site visited.
  • Free-webmail developer (gmail) with no verified identity or business website; featured badge but no publisher verification.
  • Dynamic <script src> creation in bundled jQuery combined with no CSP raises remote-code-loading risk.

Evidence

  • broad_host_access manifest host_permissions and content_scripts_matches both set to *://*/* — extension touches every site.
  • generic_privacy_policy store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • cve_jquery_medium_x3 crx jquery@1.10.2 has CVE-2019-11358, CVE-2020-11023, CVE-2015-9251 (all moderate); none fixed at bundled version.
  • no_csp manifest csp_present=false; no content_security_policy declared, amplifying CVE and dynamic-script risk.
  • script_src_dynamic crx Dynamic <script src> detected in jquery.min.js — code_quality gets +3.0 for script_src_dynamic signal.
  • free_webmail_dev store Developer email micthelldawsen7@gmail.com; no business website; +1.5 reputation penalty applied.
  • featured_badge store is_featured_by_google=true; applies -2.0 reputation discount but does not override other risk signals.
  • js_external_hosts crx 9 distinct external JS hosts (buzz.jaysalvat.com, facebook.com, vk.com, etc.); >3 distinct domains raises network score.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@1.10.2 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11023 jquery@1.10.2 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.10.2 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • *://*/* (host_permissions) high Broad host access to all URLs; content scripts also injected everywhere.
  • *://*/* (content_scripts_matches) high Content scripts run on every page, enabling DOM access and data capture site-wide.

Pillar Scores

Permissions6.00
Reputation7.00
Network5.50
Webstore3.50
Maintenance1.50
Privacy10.00
Code Quality6.00
CVE Exposure4.50

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 10:46
Listing SHA 350c4143170f…
Force block — not fired
Score recovered no
Elapsed