Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

SNES Mate - SNES Emulator

jjhepmoeblmpiecjclakeeolfdemhepb
Risk Score
4.70
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 67
Rating 5.0
Last updated 2026-08-09 (1 months ago)
Manifest version MV3
CSP present ✅ yes
Developer hunkiepeanut.dev@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • declarativeNetRequestWithHostAccess + <all_urls> allows interception/modification of all network traffic on every site.
  • Content scripts injected on all URLs give broad page-content access despite emulator category.
  • Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and third-party sharing.
  • External JS hosts include raw.githubusercontent.com and cdn.emulatorjs.org enabling remote code pull at runtime.
  • Free-webmail developer (gmail) with no verified publisher and 67 installs but high-impact permissions (tail attack surface).

Evidence

  • high_permissions_broad_host manifest declarativeNetRequestWithHostAccess + <all_urls> host_permissions + content_scripts on <all_urls>; ×1.2 multiplier applied.
  • generic_privacy_policy store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy pillar (v3.5 rule D).
  • free_webmail_dev_no_business store Developer email hunkiepeanut.dev@gmail.com; no verified publisher, no business domain; reputation floor applies.
  • eval_user_input_in_sandbox crx eval_user_input found in extract7z.js and extractzip.js; sandbox CSP allows unsafe-eval which mitigates but does not eliminate risk.
  • external_js_hosts crx 8 external hosts including raw.githubusercontent.com, cdn.emulatorjs.org, socket.io — remote code loading surface.
  • small_install_high_perm api 67 installs with HIGH-tier permissions (declarativeNetRequestWithHostAccess + <all_urls>); install_perm_anomaly confirmed.
  • csp_sandbox_unsafe_eval manifest Sandbox CSP includes unsafe-eval and unsafe-inline; extension_pages CSP is tighter (wasm-unsafe-eval only).
  • wayback_no_snapshot api No Wayback Machine snapshot found; extension history unverifiable.

Permissions Breakdown

  • storage low Standard save-state/ROM persistence; expected for emulator.
  • unlimitedStorage low ROMs are large; expected for emulator use case.
  • alarms low Periodic tasks; low standalone risk.
  • declarativeNetRequestWithHostAccess high Can intercept/modify network requests on all URLs; high capability.
  • <all_urls> (host_permissions) high Full host access; pairs with declarativeNetRequestWithHostAccess for broad reach ×1.2.
  • <all_urls> (content_scripts) high Content scripts injected on every site; can read/modify any page.

Pillar Scores

Permissions7.50
Reputation7.00
Network5.50
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 13:25
Listing SHA caa7d79c1c02…
Force block — not fired
Score recovered no
Elapsed