Infinite Mario Bros Offline
iiclalbandeleomiglahokbnnlmbajpl
Risk Score
4.77
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- jquery@1.4.2 bundles 6 moderate CVEs (XSS); no CSP amplifies exploit risk via jquery<3.5+no-CSP rule
- Privacy policy on unblockedgames6x.org admits data collection and 3rd-party sharing without extension-specific scope (+10.0)
- Uninstall URL hijack detected — extension registers uninstall callback to external destination
- Install URL hijack opens infinite.html on install — low-grade onInstalled redirect pattern
- Developer uses free-webmail (gmail), no developer name, and policy domain is unverified game portal
Evidence
- cve_moderate_x6_jquery_1.4.2 crx 6 moderate CVEs in jquery@1.4.2 (XSS). fixed_in ranges 1.6.3–3.5.0; bundled version far below all fixed_in.
- privacy_policy_generic_admits_sharing store Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (D rule).
- uninstall_url_hijack crx chrome.runtime.setUninstallURL() registered; target null in data but flag is true → +3.0 webstore.
- install_url_hijack crx onInstalled opens infinite.html → +2.0 webstore.
- function_constructor_in_jquery crx new Function() in jquery.min.js → +2.5 code quality (function_constructor signal).
- js_external_hosts_unblockedgames crx js_external_hosts includes unblockedgames6x.org; no CSP; MV3 but no CSP declared → +2.0 network (MV2+no-CSP rule not applied; base connect-src broad not triggered).
- reputation_free_webmail_no_devname store developer_email=nwifigames@gmail.com, developer_name empty. Verified+featured → floor 2.0, then +1.5 free-webmail penalty applied.
- maintenance_21mo_stale store 21 months since update → +6.0 maintenance pillar (12-24mo band). Invariant 0c caps verified discount to -1.0 due to stale >18mo.
CVE Exposures (6)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2012-6708 | jquery@1.4.2 | moderate | 1.9.0 | Cross-Site Scripting in jquery |
| CVE-2011-4969 | jquery@1.4.2 | moderate | 1.6.3 | jQuery vulnerable to Cross-Site Scripting (XSS) |
| CVE-2019-11358 | jquery@1.4.2 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11023 | jquery@1.4.2 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-7656 | jquery@1.4.2 | moderate | 1.9.0 | Cross-Site Scripting in jquery |
| CVE-2015-9251 | jquery@1.4.2 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Pillar Scores
Permissions0.00
Reputation4.50
Network2.00
Webstore5.50
Maintenance6.00
Privacy10.00
Code Quality2.50
CVE Exposure5.25
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 14:35
Listing SHA
a6c3f115cb61…
Force block
— not fired
Score recovered
no
Elapsed
—