Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

High or Low Casino Game

ijccacgjefefdpglhclnbpfjlcbagafm
Risk Score
4.43
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 573
Rating 5.0
Last updated 2026-04-20 (4 months ago)
Manifest version MV3
CSP present ✅ yes
Developer nadejdinv@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall URL hijack + install URL hijack flags monetization/tracking shell pattern
  • Privacy policy on CDN subdomain (cloudapi.stream), not scoped to this extension, mentions 3rd-party sharing
  • jquery@3.2.1 bundles 3 moderate CVEs (XSS); not patched to fixed_in versions
  • Free-webmail developer (gmail), no developer name, no verified publisher
  • 11 external JS hosts referenced; sandbox CSP allows unsafe-eval/unsafe-inline

Evidence

  • uninstall_url_hijack + install_url_hijack crx Both install and uninstall URL hooks present; classic monetization/redirect shell fingerprint.
  • free_webmail_no_dev_name store Developer nadejdinv@gmail.com, no developer_name field; unverified, no business identity.
  • privacy_policy_cdn_not_scoped store Policy at cdn.cloudapi.stream; scope_extension=false, third_party_sharing=true, data_collection=false.
  • jquery_cve_triple crx jquery@3.2.1 carries CVE-2019-11358, CVE-2020-11022, CVE-2020-11023 (all moderate XSS); fixed in 3.5.0.
  • sandbox_csp_unsafe manifest Sandbox CSP allows unsafe-inline and unsafe-eval on script-src; elevates XSS risk from bundled jQuery CVEs.
  • 11_external_js_hosts crx js_external_hosts lists 11 domains including goo.gl, cloudapi.stream, codecanyon.net; wide third-party surface.
  • empty_permissions manifest No declared permissions or host_permissions; extension is a self-contained popup game reducing CAPABILITY risk.
  • low_installs store 573 installs; blast radius is low but URL hijack signals and gmail dev merit scrutiny.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@3.2.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.2.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.2.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Pillar Scores

Permissions0.00
Reputation7.00
Network0.00
Webstore9.00
Maintenance1.50
Privacy9.00
Code Quality2.00
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 08:45
Listing SHA bdcf3109ef93…
Force block — not fired
Score recovered no
Elapsed