1930
mbcibgkijjmnhbbheafplbapiacgkebe
Risk Score
5.27
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Extension not updated for 36 months; abandoned with 40K installs creates supply-chain target.
- jquery@3.4.1 bundles two medium XSS CVEs (CVE-2020-11022, CVE-2020-11023); no CSP amplifies risk.
- Uninstall URL hijack flag set — may redirect users to third-party page on removal.
- Install URL hijack flag set — opens third-party URL on installation.
- Developer uses free-webmail (proton.me) with privacy policy on unrelated domain w3technic.com; no retention disclosure.
Evidence
- no_permissions manifest No declared permissions or host_permissions; game likely self-contained.
- jquery_cve crx jquery@3.4.1 bundles CVE-2020-11022 and CVE-2020-11023 (XSS); fixed in 3.5.0.
- no_csp manifest content_security_policy is null on MV3; amplifies XSS CVE risk.
- uninstall_url_hijack crx install_url_hijack and uninstall_url_hijack both true; targets not disclosed.
- stale_extension store Last updated June 2023; 36 months since update — maintenance score maximum.
- free_webmail_dev store Developer email contactofflinegames@proton.me; free webmail, no verified business domain.
- privacy_policy_no_retention api Policy fetched, scoped, data_collection=true but retention=false and third_party_silence=true.
- external_hosts crx JS contacts example.com, www.construct.net, www.w3technic.com; no bad-host hits.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2020-11022 | jquery@3.4.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.4.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Pillar Scores
Permissions0.00
Reputation6.50
Network0.00
Webstore6.00
Maintenance10.00
Privacy2.00
Code Quality2.00
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:54
Listing SHA
e8742ea773b5…
Force block
— not fired
Score recovered
no
Elapsed
18.3s