Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Mini Golf World

kblomapfkjidbbbdllmofkcakcenkmec
Risk Score
3.22
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Entertainment
Installs 613
Rating 5.0
Last updated 2026-04-27 (4 months ago)
Manifest version MV3
CSP present ✅ yes
Developer kiev3381917@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy not scoped to this extension and hosted on dev CDN; third-party sharing admitted without extension scope.
  • Uninstall URL hijack flag set — attempts to capture uninstall events for redirect.
  • Three medium-severity jQuery CVEs (3.2.1) bundled; fixed version is 3.5.0.
  • Developer uses free Gmail with no verified publisher status; throwaway-pattern email.
  • Sandbox CSP permits unsafe-eval and unsafe-inline, weakening XSS mitigations for sandboxed pages.

Evidence

  • uninstall_url_hijack crx chrome.runtime.setUninstallURL() called; uninstall_url_hijack=true per scan.
  • install_url_hijack crx install_url_hijack=true, opens popup/index.html on install (internal target, lower severity).
  • jquery_cve_bundle crx jquery@3.2.1 bundled with 3 medium CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); fixed in 3.5.0.
  • privacy_policy_inadequate store Policy fetched from CDN; scope_extension=false, data_collection=false but third_party_sharing=true.
  • sandbox_csp_unsafe crx Sandbox CSP allows unsafe-eval and unsafe-inline on script-src, weakening sandboxed page security.
  • free_webmail_developer store Developer email kiev3381917@gmail.com; no verified publisher; no business domain.
  • js_external_hosts crx 10 external JS hosts referenced incl. bnjmnt4n.now.sh, goo.gl, harrytheo.com — broad external surface.
  • host_geo_diversity crx JS hosted across 3 countries (CA, NL, US); country_count=3, below +1.5 threshold of 4.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@3.2.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.2.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.2.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • host: https://www.googleapis.com/* medium Access to Google APIs; moderate risk depending on use.
  • host: https://wheel.cloudapi.stream/* medium Access to developer-controlled CDN domain; data exfil possible.
  • host: https://mines.cloudapi.stream/* medium Second developer-controlled CDN endpoint; same exfil concern.

Pillar Scores

Permissions2.00
Reputation6.50
Network2.00
Webstore5.00
Maintenance1.50
Privacy9.00
Code Quality0.00
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 08:57
Listing SHA cf42841ccc7f…
Force block — not fired
Score recovered no
Elapsed