Stacker - Falling Block
jhjomhjgolkejjhnglnammeflgedabbo
Risk Score
2.19
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Install and uninstall URL hijack both active — extension redirects users on install/uninstall.
- Privacy policy admits data collection and third-party sharing but is not scoped to this extension (generic site policy).
- jquery@3.4.1 bundled with two medium-severity XSS CVEs (fixed in 3.5.0); no CSP present.
- Free-webmail developer (gmail), no developer name listed, no verified business identity.
- External JS hosts include unblockedgames6x.org and construct.net — game portal shell pattern.
Evidence
- install_url_hijack + uninstall_url_hijack crx Both install and uninstall URL hijacks flagged; targets null but behavior is present — monetization shell pattern.
- privacy_policy_scope_mismatch store Policy on unblockedgames6x.org: fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true.
- cve_jquery_xss crx jquery@3.4.1 has CVE-2020-11022 and CVE-2020-11023 (moderate XSS); fixed in 3.5.0. No CSP present.
- game_portal_shell crx js_external_hosts include unblockedgames6x.org and construct.net — classic game-portal extension shell.
- developer_identity store dev=nwifigames@gmail.com, no developer_name, free-webmail only. verified_publisher and is_featured_by_google both true.
- no_csp crx content_security_policy is null; csp_present=false. Increases XSS risk from CVE-vulnerable jQuery.
- manifest_localization_only crx manifest_name and manifest_description are localization keys (__MSG_appName__), no direct readable metadata.
- verified_publisher_featured store Extension carries verified_publisher and is_featured_by_google badges, reducing reputation risk partially.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2020-11022 | jquery@3.4.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.4.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Pillar Scores
Permissions0.00
Reputation3.50
Network0.00
Webstore7.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 14:45
Listing SHA
88d5aa5a206f…
Force block
— not fired
Score recovered
no
Elapsed
—