flappy birdie (night farm mode)
hpkfkbmcphnigepfjmapkdaedglohgjg
Risk Score
5.55
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's own account policy — not scoped to this extension at all; admits data collection and 3rd-party sharing.
- jquery@1.10.2 bundles 3 unpatched medium-severity XSS CVEs (unfixed); no CSP amplifies risk.
- Content scripts injected on *://*/* give full DOM read/write access to every site visited.
- Free-webmail developer (gmail) with no verified identity or business website; featured badge but no publisher verification.
- Dynamic <script src> creation in bundled jQuery combined with no CSP raises remote-code-loading risk.
Evidence
- broad_host_access manifest host_permissions and content_scripts_matches both set to *://*/* — extension touches every site.
- generic_privacy_policy store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
- cve_jquery_medium_x3 crx jquery@1.10.2 has CVE-2019-11358, CVE-2020-11023, CVE-2015-9251 (all moderate); none fixed at bundled version.
- no_csp manifest csp_present=false; no content_security_policy declared, amplifying CVE and dynamic-script risk.
- script_src_dynamic crx Dynamic <script src> detected in jquery.min.js — code_quality gets +3.0 for script_src_dynamic signal.
- free_webmail_dev store Developer email micthelldawsen7@gmail.com; no business website; +1.5 reputation penalty applied.
- featured_badge store is_featured_by_google=true; applies -2.0 reputation discount but does not override other risk signals.
- js_external_hosts crx 9 distinct external JS hosts (buzz.jaysalvat.com, facebook.com, vk.com, etc.); >3 distinct domains raises network score.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@1.10.2 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11023 | jquery@1.10.2 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@1.10.2 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- *://*/* (host_permissions) high Broad host access to all URLs; content scripts also injected everywhere.
- *://*/* (content_scripts_matches) high Content scripts run on every page, enabling DOM access and data capture site-wide.
Pillar Scores
Permissions6.00
Reputation7.00
Network5.50
Webstore3.50
Maintenance1.50
Privacy10.00
Code Quality6.00
CVE Exposure4.50
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 10:46
Listing SHA
350c4143170f…
Force block
— not fired
Score recovered
no
Elapsed
—