Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

1930

mbcibgkijjmnhbbheafplbapiacgkebe
Risk Score
5.27
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 40,000
Rating 4.6
Last updated 2023-06-01 (36 months ago)
Manifest version MV3
CSP present ❌ no
Developer contactofflinegames@proton.me
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Extension not updated for 36 months; abandoned with 40K installs creates supply-chain target.
  • jquery@3.4.1 bundles two medium XSS CVEs (CVE-2020-11022, CVE-2020-11023); no CSP amplifies risk.
  • Uninstall URL hijack flag set — may redirect users to third-party page on removal.
  • Install URL hijack flag set — opens third-party URL on installation.
  • Developer uses free-webmail (proton.me) with privacy policy on unrelated domain w3technic.com; no retention disclosure.

Evidence

  • no_permissions manifest No declared permissions or host_permissions; game likely self-contained.
  • jquery_cve crx jquery@3.4.1 bundles CVE-2020-11022 and CVE-2020-11023 (XSS); fixed in 3.5.0.
  • no_csp manifest content_security_policy is null on MV3; amplifies XSS CVE risk.
  • uninstall_url_hijack crx install_url_hijack and uninstall_url_hijack both true; targets not disclosed.
  • stale_extension store Last updated June 2023; 36 months since update — maintenance score maximum.
  • free_webmail_dev store Developer email contactofflinegames@proton.me; free webmail, no verified business domain.
  • privacy_policy_no_retention api Policy fetched, scoped, data_collection=true but retention=false and third_party_silence=true.
  • external_hosts crx JS contacts example.com, www.construct.net, www.w3technic.com; no bad-host hits.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2020-11022 jquery@3.4.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.4.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Pillar Scores

Permissions0.00
Reputation6.50
Network0.00
Webstore6.00
Maintenance10.00
Privacy2.00
Code Quality2.00
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:54
Listing SHA e8742ea773b5…
Force block — not fired
Score recovered no
Elapsed 18.3s