Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Pinball Space Adventure Game

iibghlclocgeljpbimnneepjceaiepkj
Risk Score
5.79
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 40,000
Rating 4.2
Last updated 2023-11-23 (31 months ago)
Manifest version MV3
CSP present ❌ no
Developer mcdadeheadeu@hotmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall URL hijack and install URL hijack signals monetization shell pattern
  • Privacy policy is from retrobowl.me (unrelated domain), admits data collection and 3rd-party sharing without scoping to this extension
  • jquery@3.2.1 has 3 medium-severity CVEs (XSS); no CSP amplifies risk
  • Developer uses free webmail (hotmail.com), no developer name, no business domain
  • Extension stale 31 months with no CSP and vulnerable bundled jQuery

Evidence

  • install_url_hijack crx install_url_hijack=true; opens 3rd-party URL on install — monetization shell signal
  • uninstall_url_hijack crx uninstall_url_hijack=true; redirects to 3rd-party URL on uninstall
  • privacy_policy_mismatch store Policy hosted at retrobowl.me (unrelated game site); scope_extension=false, data_collection=true, third_party_sharing=true
  • cve_jquery crx jquery@3.2.1 bundles 3 medium CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); no CSP present
  • developer_identity store Developer email mcdadeheadeu@hotmail.com; no developer name; free webmail; no business domain
  • staleness store Last updated November 2023; 31 months stale with known-vulnerable jQuery and no CSP
  • external_hosts crx 6 external JS hosts: bnjmnt4n.now.sh, createjs.com, mths.be, www.gphysics.com, www.opensource.org, www.w3technic.com
  • verified_publisher_featured store verified_publisher=true and is_featured_by_google=true, but stale >18mo and CVEs present — discount capped at -1.0 per invariant 0c/v3.5E

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@3.2.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.2.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.2.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Pillar Scores

Permissions0.00
Reputation6.50
Network2.50
Webstore7.00
Maintenance8.50
Privacy10.00
Code Quality4.00
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:43
Listing SHA 685a3578217d…
Force block — not fired
Score recovered no
Elapsed 45.1s