Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Helix Fruit Jump Arcade Game

jhegmncopobmnnmcdaobcepcamekoomb
Risk Score
4.71
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 200,000
Rating 4.1
Last updated 2023-10-08 (32 months ago)
Manifest version MV3
CSP present ✅ yes
Developer info@gamebol.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but not scoped to this extension and admits data collection + third-party sharing → Privacy pillar 10.0
  • Extension last updated 32 months ago; zombie game extension with 200K installs → Maintenance 8.5
  • Uninstall URL hijack redirects to gamebol.com/helix-fruit-jump/ — tracks uninstall events
  • Install URL hijack opens /Game_Source/index.html on install — onInstalled redirect signal
  • No developer display name; operator cluster shows 2 siblings on dev_email / install_url dims

Evidence

  • uninstall_url_hijack crx chrome.runtime.setUninstallURL targets https://gamebol.com/helix-fruit-jump/ — tracks uninstall events to 3rd party page
  • install_url_hijack crx onInstalled opens /Game_Source/index.html — non-3rd-party but still an install redirect pattern
  • privacy_policy_not_scoped store Policy fetched (8726 chars), data_collection=true, third_party_sharing=true, scope_extension=false → v3.5 rule D: +10.0
  • maintenance_stale store Last updated October 2023, 32 months ago. MV3 game extension with 200K installs, no recent security patches.
  • operator_cluster_siblings api sibling_count=0 at compound level but dev_email and install_url dims each show 2 siblings — same operator runs other extensions
  • no_developer_name store developer_name is empty string; Reputation starts +1.0 for missing 'Offered by' name
  • verified_publisher store verified_publisher=true AND is_featured_by_google=true; discount capped at -1.0 under v3.5 invariant 0c (months_since_update=32 > 18)
  • cve_clean crx cve_findings_raw empty, code_findings_raw empty, obfuscation_score=0.0 — no code-level risk detected

Pillar Scores

Permissions0.00
Reputation2.00
Network0.00
Webstore6.00
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:45
Listing SHA 26b0456404ed…
Force block — not fired
Score recovered no
Elapsed 19.0s