Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Elden Ring DLC Live Wallpaper

aghakeajkajbjonfkdicogjgbgffdbfa
Risk Score
5.85
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category NewTab
Installs 161
Rating 5.0
Last updated 2025-08-27 (13 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@gameograf.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • NewTab override with uninstall URL hijack and install URL hijack — classic monetization shell pattern.
  • Privacy policy is Google's generic policy (scope_extension=false, data_collection=true, third_party_sharing=true) — +10 privacy score.
  • No developer name listed despite verified publisher status; missing branding accountability.
  • newtab override + search permission combo enables persistent ad/search monetization across all sessions.
  • DOM-XSS sinks (innerHTML from variable) in calendar.js and popup.js with no CSP present.

Evidence

  • newtab_override manifest chrome_url_overrides.newtab set to newtab.html — high-reach replacement of every new tab page.
  • uninstall_url_hijack crx Uninstall URL redirects to gameograf.com with UTM tracking params — monetization signal.
  • install_url_hijack crx Install URL opens gameograf.com with UTM params — monetization shell pattern.
  • generic_privacy_policy store Privacy policy is Google's own policy (myaccount.google.com); scope_extension=false, data_collection=true, third_party_sharing=true.
  • no_developer_name store developer_name is empty string despite verified_publisher=true; accountability gap.
  • dom_xss_sinks crx Two innerHTML-from-variable sinks in calendar.js and popup.js; no CSP to mitigate.
  • maintenance_stale store 13 months since last update; falls in 12-24mo band (+6.0 maintenance).
  • newtab_monetization_pattern manifest search permission + newtab override + install/uninstall URL hijacks = full monetization shell fingerprint.

Permissions Breakdown

  • search medium Can manipulate browser search behavior; paired with newtab override increases monetization risk.
  • https://api.gameograf.com/* medium Host permission to developer API; scoped but enables data exfiltration to dev-controlled endpoint.
  • chrome_url_overrides.newtab medium Replaces every new tab; high-reach surface for ad monetization and tracking injection.

Pillar Scores

Permissions5.00
Reputation5.00
Network2.00
Webstore8.50
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 10:59
Listing SHA 80cfcc09b618…
Force block — not fired
Score recovered no
Elapsed