Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Ponyo Wallpapers

bnmobfhfbagiomlphadlgdakbkfehnke
Risk Score
5.56
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category NewTab
Installs 951
Rating 4.2
Last updated 2025-07-10 (14 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@gameograf.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Google's own privacy policy used — completely unscoped to this extension, admits data collection and 3rd-party sharing.
  • New-tab override with uninstall URL hijack and install URL hijack — classic monetization shell pattern.
  • bit.ly affiliate/cloaking link in external JS hosts — cloaked redirect destination unverifiable.
  • mlionltd.github.io as external JS host — third-party GitHub Pages domain with no clear ownership.
  • No developer name listed and privacy policy is Google's generic policy, not extension-specific.

Evidence

  • privacy_policy_generic_google store Policy URL is myaccount.google.com/privacypolicy — Google's own policy, scope_extension=false, data_collection=true, third_party_sharing=true.
  • newtab_override_with_monetization_hijacks manifest chrome_url_overrides.newtab=index.html; uninstall_url_hijack and install_url_hijack both true pointing to gameograf.com UTM URLs.
  • affiliate_hit_bitly crx bit.ly in js_external_hosts — affiliate/cloaking redirector per threat_intel.affiliate_hits.
  • external_host_github_pages crx mlionltd.github.io in js_external_hosts — uncontrolled third-party GitHub Pages domain.
  • dom_xss_sink crx dom_sink_innerhtml_userctrl in js/popup.js with no CSP — elevated DOM-XSS risk.
  • no_developer_name store developer_name is empty string; verified_publisher=true but no displayed name.
  • maintenance_stale store months_since_update=14 falls in 12-24mo band (+6.0 maintenance score).
  • no_csp manifest content_security_policy is null; MV3 provides defaults but dom_sink_innerhtml_userctrl is higher risk without explicit CSP.

Permissions Breakdown

  • search medium Allows querying/overriding search; combined with newtab override raises monetization risk.
  • chrome_url_overrides.newtab high Replaces every new tab — primary surface for ad/search monetization shells.
  • host_permissions: https://api.gameograf.com/* low Scoped to dev-controlled API domain; limited blast radius.

Pillar Scores

Permissions4.00
Reputation5.50
Network2.50
Webstore7.50
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 06:02
Listing SHA 88c550b44e56…
Force block — not fired
Score recovered no
Elapsed