Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

2048 Classic Game

kgfeiebnfmmfpomhochmlfmdmjmfedfj
Risk Score
5.53
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 30,000
Rating 4.0
Last updated 2026-02-07 (6 months ago)
Manifest version MV3
CSP present ❌ no
Developer matthewwatson24648@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Game extension claims <all_urls> host access and injects content scripts on every site — severe capability mismatch.
  • Privacy policy is Google's generic account policy; scope_extension=false, data_collection=true, third_party_sharing=true — worst-case Privacy score.
  • Developer uses free Gmail with no business presence; unverified identity for an extension with broad access.
  • External JS host includes github.com alongside Google Analytics — no CSP to constrain remote loading.
  • is_featured_by_google=true but broad permissions + generic privacy policy still present significant residual risk.

Evidence

  • broad_host_access_mismatch manifest <all_urls> host_permissions + content_scripts on all URLs declared for a simple 2048 game — clear scope mismatch.
  • generic_privacy_policy store Privacy policy points to Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • free_webmail_developer store Developer email matthewwatson24648@gmail.com; no business domain; no verified publisher badge.
  • external_js_hosts crx JS contacts github.com and www.google-analytics.com; no CSP present on MV3 extension.
  • google_analytics_telemetry api monetization_hits: google-analytics telemetry; only telemetry-tier hit, single domain.
  • featured_by_google store is_featured_by_google=true; provides partial trust discount but not verified publisher.
  • no_cve_findings crx cve_findings_raw empty; no known vulnerable libraries bundled.
  • maintenance_3_6_months store months_since_update=6; borderline 3-6 month stale band; +1.5 maintenance score.

Permissions Breakdown

  • storage low Stores game state locally; low risk.
  • scripting medium Can inject scripts into pages; medium risk without broader context.
  • alarms low Schedules background tasks; low risk.
  • <all_urls> (host_permissions) high Broad host access on all URLs; mismatched for a game extension.
  • <all_urls> (content_scripts) high Content scripts injected on every site; high capability for a game.

Pillar Scores

Permissions7.00
Reputation6.50
Network4.00
Webstore5.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 07:58
Listing SHA ca0b8f556d5f…
Force block — not fired
Score recovered no
Elapsed