Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Infinite Mario Bros Offline

iiclalbandeleomiglahokbnnlmbajpl
Risk Score
4.77
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 1,000
Rating 4.5
Last updated 2024-11-13 (21 months ago)
Manifest version MV3
CSP present ❌ no
Developer nwifigames@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • jquery@1.4.2 bundles 6 moderate CVEs (XSS); no CSP amplifies exploit risk via jquery<3.5+no-CSP rule
  • Privacy policy on unblockedgames6x.org admits data collection and 3rd-party sharing without extension-specific scope (+10.0)
  • Uninstall URL hijack detected — extension registers uninstall callback to external destination
  • Install URL hijack opens infinite.html on install — low-grade onInstalled redirect pattern
  • Developer uses free-webmail (gmail), no developer name, and policy domain is unverified game portal

Evidence

  • cve_moderate_x6_jquery_1.4.2 crx 6 moderate CVEs in jquery@1.4.2 (XSS). fixed_in ranges 1.6.3–3.5.0; bundled version far below all fixed_in.
  • privacy_policy_generic_admits_sharing store Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (D rule).
  • uninstall_url_hijack crx chrome.runtime.setUninstallURL() registered; target null in data but flag is true → +3.0 webstore.
  • install_url_hijack crx onInstalled opens infinite.html → +2.0 webstore.
  • function_constructor_in_jquery crx new Function() in jquery.min.js → +2.5 code quality (function_constructor signal).
  • js_external_hosts_unblockedgames crx js_external_hosts includes unblockedgames6x.org; no CSP; MV3 but no CSP declared → +2.0 network (MV2+no-CSP rule not applied; base connect-src broad not triggered).
  • reputation_free_webmail_no_devname store developer_email=nwifigames@gmail.com, developer_name empty. Verified+featured → floor 2.0, then +1.5 free-webmail penalty applied.
  • maintenance_21mo_stale store 21 months since update → +6.0 maintenance pillar (12-24mo band). Invariant 0c caps verified discount to -1.0 due to stale >18mo.

CVE Exposures (6)

CVELibrarySeverity Fixed inSummary
CVE-2012-6708 jquery@1.4.2 moderate 1.9.0 Cross-Site Scripting in jquery
CVE-2011-4969 jquery@1.4.2 moderate 1.6.3 jQuery vulnerable to Cross-Site Scripting (XSS)
CVE-2019-11358 jquery@1.4.2 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11023 jquery@1.4.2 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-7656 jquery@1.4.2 moderate 1.9.0 Cross-Site Scripting in jquery
CVE-2015-9251 jquery@1.4.2 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Pillar Scores

Permissions0.00
Reputation4.50
Network2.00
Webstore5.50
Maintenance6.00
Privacy10.00
Code Quality2.50
CVE Exposure5.25

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 14:35
Listing SHA a6c3f115cb61…
Force block — not fired
Score recovered no
Elapsed