Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Stacker - Falling Block

jhjomhjgolkejjhnglnammeflgedabbo
Risk Score
2.19
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Entertainment
Installs 2,000
Rating 5.0
Last updated 2026-06-16 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer nwifigames@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Install and uninstall URL hijack both active — extension redirects users on install/uninstall.
  • Privacy policy admits data collection and third-party sharing but is not scoped to this extension (generic site policy).
  • jquery@3.4.1 bundled with two medium-severity XSS CVEs (fixed in 3.5.0); no CSP present.
  • Free-webmail developer (gmail), no developer name listed, no verified business identity.
  • External JS hosts include unblockedgames6x.org and construct.net — game portal shell pattern.

Evidence

  • install_url_hijack + uninstall_url_hijack crx Both install and uninstall URL hijacks flagged; targets null but behavior is present — monetization shell pattern.
  • privacy_policy_scope_mismatch store Policy on unblockedgames6x.org: fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true.
  • cve_jquery_xss crx jquery@3.4.1 has CVE-2020-11022 and CVE-2020-11023 (moderate XSS); fixed in 3.5.0. No CSP present.
  • game_portal_shell crx js_external_hosts include unblockedgames6x.org and construct.net — classic game-portal extension shell.
  • developer_identity store dev=nwifigames@gmail.com, no developer_name, free-webmail only. verified_publisher and is_featured_by_google both true.
  • no_csp crx content_security_policy is null; csp_present=false. Increases XSS risk from CVE-vulnerable jQuery.
  • manifest_localization_only crx manifest_name and manifest_description are localization keys (__MSG_appName__), no direct readable metadata.
  • verified_publisher_featured store Extension carries verified_publisher and is_featured_by_google badges, reducing reputation risk partially.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2020-11022 jquery@3.4.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.4.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Pillar Scores

Permissions0.00
Reputation3.50
Network0.00
Webstore7.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 14:45
Listing SHA 88d5aa5a206f…
Force block — not fired
Score recovered no
Elapsed