Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Denji Chainsaw Man New Tab Extension

aphghkpebkfklfjjdolmfecaleiopife
Risk Score
6.22
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category NewTab
Installs 1,000
Rating 4.0
Last updated 2025-05-06 (16 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@gameograf.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's own policy — not scoped to this extension; admits data collection and 3rd-party sharing (Privacy pillar: 10.0).
  • NewTab override + uninstall URL hijack to gameograf.com = classic fan-theme monetization shell pattern.
  • 9 moderate CVEs across jquery@1.9.1, jquery@3.4.1, and jquery-ui@1.12.1 — all below fixed_in versions; no CSP amplifies XSS risk.
  • Uninstall URL redirects to gameograf.com UTM-tracked endpoint; dev email cluster has 15 siblings by dev_email and 10 by uninstall_url.
  • No CSP present (MV3 default strictness does not cover bundled libs); 16 months stale with multiple vulnerable DOM-manipulation libs.

Evidence

  • newtab_override manifest chrome_url_overrides.newtab set to index.html — replaces every new tab page.
  • uninstall_url_hijack crx setUninstallURL points to gameograf.com with UTM tracking params.
  • generic_privacy_policy store Privacy policy URL is Google's own policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • cve_moderate_bulk crx 9 moderate CVEs in bundled jquery@1.9.1, jquery@3.4.1, jquery-ui@1.12.1; none at fixed_in version.
  • no_csp manifest content_security_policy is null; no CSP amplifies XSS risk from vulnerable jQuery versions.
  • operator_cluster_siblings api dev_email dimension shows 15 sibling extensions under info@gameograf.com; uninstall_url dimension shows 10.
  • stale_extension store Last updated May 2025 but months_since_update=16; CVE-laden libs unpatched across that period.
  • fan_theme_shell store Anime-character NewTab with no functional utility beyond wallpaper; matches fan-content/theme shell pattern.

CVE Exposures (9)

CVELibrarySeverity Fixed inSummary
CVE-2021-41182 jquery-ui@1.12.1 moderate 1.13.0 XSS in the `altField` option of the Datepicker widget in jquery-ui
CVE-2021-41184 jquery-ui@1.12.1 moderate 1.13.0 XSS in the `of` option of the `.position()` util in jquery-ui
CVE-2022-31160 jquery-ui@1.12.1 moderate 1.13.2 jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like in
CVE-2021-41183 jquery-ui@1.12.1 moderate 1.13.0 XSS in `*Text` options of the Datepicker widget in jquery-ui
CVE-2020-11022 jquery@3.4.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.4.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2019-11358 jquery@1.9.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11023 jquery@1.9.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.9.1 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • search medium Allows querying browser search API; relevant to NewTab/search override context.
  • topSites medium Reads user's most visited sites; privacy-relevant browsing data.
  • unlimitedStorage low Allows storing large amounts of local data; low standalone risk.
  • storage low Standard local/sync storage; low risk.
  • chrome_url_overrides.newtab high Replaces every new tab; high-reach entry point for ad/affiliate monetization.

Pillar Scores

Permissions3.50
Reputation5.00
Network3.50
Webstore7.50
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure5.25

Bookkeeping

Rubric v3.6
Scored at 2026-09-16 03:20
Listing SHA 9563ef428de9…
Force block — not fired
Score recovered no
Elapsed