Pinball Space Adventure Game
iibghlclocgeljpbimnneepjceaiepkj
Risk Score
5.79
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Uninstall URL hijack and install URL hijack signals monetization shell pattern
- Privacy policy is from retrobowl.me (unrelated domain), admits data collection and 3rd-party sharing without scoping to this extension
- jquery@3.2.1 has 3 medium-severity CVEs (XSS); no CSP amplifies risk
- Developer uses free webmail (hotmail.com), no developer name, no business domain
- Extension stale 31 months with no CSP and vulnerable bundled jQuery
Evidence
- install_url_hijack crx install_url_hijack=true; opens 3rd-party URL on install — monetization shell signal
- uninstall_url_hijack crx uninstall_url_hijack=true; redirects to 3rd-party URL on uninstall
- privacy_policy_mismatch store Policy hosted at retrobowl.me (unrelated game site); scope_extension=false, data_collection=true, third_party_sharing=true
- cve_jquery crx jquery@3.2.1 bundles 3 medium CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); no CSP present
- developer_identity store Developer email mcdadeheadeu@hotmail.com; no developer name; free webmail; no business domain
- staleness store Last updated November 2023; 31 months stale with known-vulnerable jQuery and no CSP
- external_hosts crx 6 external JS hosts: bnjmnt4n.now.sh, createjs.com, mths.be, www.gphysics.com, www.opensource.org, www.w3technic.com
- verified_publisher_featured store verified_publisher=true and is_featured_by_google=true, but stale >18mo and CVEs present — discount capped at -1.0 per invariant 0c/v3.5E
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@3.2.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.2.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.2.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Pillar Scores
Permissions0.00
Reputation6.50
Network2.50
Webstore7.00
Maintenance8.50
Privacy10.00
Code Quality4.00
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:43
Listing SHA
685a3578217d…
Force block
— not fired
Score recovered
no
Elapsed
45.1s