SNES Mate - SNES Emulator
jjhepmoeblmpiecjclakeeolfdemhepb
Risk Score
4.70
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- declarativeNetRequestWithHostAccess + <all_urls> allows interception/modification of all network traffic on every site.
- Content scripts injected on all URLs give broad page-content access despite emulator category.
- Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and third-party sharing.
- External JS hosts include raw.githubusercontent.com and cdn.emulatorjs.org enabling remote code pull at runtime.
- Free-webmail developer (gmail) with no verified publisher and 67 installs but high-impact permissions (tail attack surface).
Evidence
- high_permissions_broad_host manifest declarativeNetRequestWithHostAccess + <all_urls> host_permissions + content_scripts on <all_urls>; ×1.2 multiplier applied.
- generic_privacy_policy store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy pillar (v3.5 rule D).
- free_webmail_dev_no_business store Developer email hunkiepeanut.dev@gmail.com; no verified publisher, no business domain; reputation floor applies.
- eval_user_input_in_sandbox crx eval_user_input found in extract7z.js and extractzip.js; sandbox CSP allows unsafe-eval which mitigates but does not eliminate risk.
- external_js_hosts crx 8 external hosts including raw.githubusercontent.com, cdn.emulatorjs.org, socket.io — remote code loading surface.
- small_install_high_perm api 67 installs with HIGH-tier permissions (declarativeNetRequestWithHostAccess + <all_urls>); install_perm_anomaly confirmed.
- csp_sandbox_unsafe_eval manifest Sandbox CSP includes unsafe-eval and unsafe-inline; extension_pages CSP is tighter (wasm-unsafe-eval only).
- wayback_no_snapshot api No Wayback Machine snapshot found; extension history unverifiable.
Permissions Breakdown
- storage low Standard save-state/ROM persistence; expected for emulator.
- unlimitedStorage low ROMs are large; expected for emulator use case.
- alarms low Periodic tasks; low standalone risk.
- declarativeNetRequestWithHostAccess high Can intercept/modify network requests on all URLs; high capability.
- <all_urls> (host_permissions) high Full host access; pairs with declarativeNetRequestWithHostAccess for broad reach ×1.2.
- <all_urls> (content_scripts) high Content scripts injected on every site; can read/modify any page.
Pillar Scores
Permissions7.50
Reputation7.00
Network5.50
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 13:25
Listing SHA
caa7d79c1c02…
Force block
— not fired
Score recovered
no
Elapsed
—