Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Uncanny Cookie Clicker

mmmdenlpgbgmeofmdkhimecmkcgabgno
Risk Score
6.21
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category Entertainment
Installs 100,000
Rating 3.8
Last updated 2023-03-14 (39 months ago)
Manifest version MV3
CSP present ❌ no
Developer builtinnya@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE-2021-23358 in bundled underscore@1.4.1 (Arbitrary Code Execution); unfixed for years.
  • Extension not updated in 39 months — stale libraries with known critical/high CVEs will never be patched.
  • Privacy policy is Google's generic account policy (scope_extension=false, admits data collection + 3rd-party sharing) — not scoped to this extension.
  • No CSP + jQuery@1.10.2 with three moderate XSS CVEs + innerHTML sink creates real DOM-XSS attack surface.
  • Free-webmail developer (gmail), no verified publisher, no business domain — unverifiable accountability.

Evidence

  • critical_cve_bundled crx underscore@1.4.1 carries CVE-2021-23358 (critical, Arbitrary Code Execution); fixed_in 1.12.1.
  • high_cve_bundled crx underscore@1.4.1 carries CVE-2026-27601 (high, DoS via unlimited recursion); fixed_in 1.13.8.
  • moderate_cves_jquery crx jquery@1.10.2 carries 3 moderate XSS CVEs (CVE-2019-11358, CVE-2020-11023, CVE-2015-9251).
  • no_csp_with_cves manifest content_security_policy is null on MV3 extension with CVE-bearing DOM-manipulation libs and innerHTML sink.
  • privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • stale_extension store Last updated March 2023 (39 months). CVE-laden libraries will never be patched at this cadence.
  • free_webmail_dev store Developer email builtinnya@gmail.com; no business domain, no verified publisher badge.
  • function_constructor_in_libs crx new Function() found in underscore.js (template engine) and jquery.js (JSON parse fallback).

CVE Exposures (5)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.4.1 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.4.1 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS
CVE-2019-11358 jquery@1.10.2 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11023 jquery@1.10.2 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.10.2 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • tabs medium Can read tab URLs and metadata; moderate risk for an entertainment helper.
  • storage low Persistent local state; low risk.
  • notifications low Can surface desktop notifications; low risk.
  • host: orteil.dashnet.org/cookieclicker/ low Scoped exclusively to the Cookie Clicker game domain; matches stated function.

Pillar Scores

Permissions1.30
Reputation6.50
Network2.00
Webstore1.00
Maintenance10.00
Privacy10.00
Code Quality5.50
CVE Exposure9.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:56
Listing SHA b454caa99e6b…
Force block — not fired
Score recovered no
Elapsed 32.4s