Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Video Poker Jacks or Better

peflgkmfmoijonfgcjdlpnnfdegnlaji
Risk Score
4.09
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 47
Rating 5.0
Last updated 2026-04-19 (4 months ago)
Manifest version MV3
CSP present ✅ yes
Developer nadejdinv@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall and install URL hijack signals indicate monetization/tracking behavior on lifecycle events.
  • Privacy policy hosted on CDN domain (cloudapi.stream), not scoped to this extension; third-party sharing admitted.
  • jquery@3.2.1 bundles 3 medium-severity XSS CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023), unfixed.
  • 7 external JS hosts including suspicious CDN (cloudapi.stream); sandbox CSP allows unsafe-eval and unsafe-inline.
  • Free-webmail developer (gmail), no developer name, no verified publisher — low accountability.

Evidence

  • install_url_hijack manifest install_url_hijack=true; target=popup/index.html — onInstalled opens internal page, pattern consistent with lifecycle tracking.
  • uninstall_url_hijack manifest uninstall_url_hijack=true; target=null — setUninstallURL() called but target not captured; monetization pattern.
  • privacy_policy_generic_cdn store Policy at cdn.cloudapi.stream: scope_extension=false, data_collection=false, third_party_sharing=true. Not scoped to extension.
  • jquery_cves crx jquery@3.2.1 has 3 medium XSS CVEs; fixed_in=3.5.0. Library not updated.
  • sandbox_csp_unsafe manifest Sandbox CSP allows unsafe-eval and unsafe-inline on script-src; elevates XSS exploitability of jquery CVEs.
  • external_hosts crx 7 external JS hosts: bnjmnt4n.now.sh, cloudapi.stream, codecanyon.net, createjs.com, mths.be, codethislab.com, opensource.org.
  • geo_diversity crx JS hosts span 4 countries (CA, IT, NL, US); triggers geo-diversity signal for Entertainment category.
  • developer_identity store Developer email nadejdinv@gmail.com; no developer name; no verified publisher; free-webmail identity.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@3.2.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.2.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.2.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Pillar Scores

Permissions0.00
Reputation7.00
Network0.00
Webstore6.50
Maintenance1.50
Privacy9.00
Code Quality2.00
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 08:59
Listing SHA e81a9ead7206…
Force block — not fired
Score recovered no
Elapsed