Super Mario Bros Classic
ojnagfkemdilpdkjehfajjmcnaefhjhn
Risk Score
4.55
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Uninstall URL hijack present — sends users to 3rd-party destination on removal.
- Install URL hijack opens play.html on installation — unsolicited page load.
- Privacy policy admits data collection and 3rd-party sharing but is not scoped to this extension.
- eval() on user-controlled input and new Function() constructor enable arbitrary code execution.
- Free-webmail developer email (gmail), no developer name, verified_publisher badge insufficient to offset identity gap.
Evidence
- uninstall_url_hijack crx uninstall_url_hijack=true; target=null. Extension registers an uninstall URL redirect.
- install_url_hijack crx install_url_hijack=true; target=play.html. Opens page on install.
- eval_user_input crx mario/ui.js: eval(x) where x is derived from onclick variable — arbitrary JS execution risk.
- function_constructor crx mario/editor.js: new Function(editor.rawfunc) executes raw user/map data as code.
- privacy_policy_scope_mismatch store Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true — admits sharing without extension scope.
- developer_identity store dev email adschallenges20xx@gmail.com (free webmail), developer_name empty, no business domain.
- verified_publisher store verified_publisher=true but discounts capped: free-webmail dev, monetization URL hijacks present.
- no_permissions_high_install_surface crx 56 JS files scanned, no declared permissions. v3.5-B anomaly: crx with no permissions but observable code surface.
Pillar Scores
Permissions0.00
Reputation7.50
Network0.00
Webstore8.50
Maintenance1.50
Privacy10.00
Code Quality5.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 16:50
Listing SHA
c18d730c4e48…
Force block
— not fired
Score recovered
no
Elapsed
—