Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Child Luffy in Winter Live Wallpaper

bpicplogeibhabicoedobpchdkngbhjh
Risk Score
5.54
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category NewTab
Installs 38
Rating 5.0
Last updated 2025-06-10 (15 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@gameograf.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • NewTab override combined with search override — classic monetization shell; installs/uninstalls tracked via UTM hijack URLs.
  • Privacy policy hosted on unrelated domain (haberikra.com), admits data collection + 3rd-party sharing, not scoped to this extension.
  • Uninstall and install URL hijack to gameograf.com with UTM parameters — explicit user-tracking on lifecycle events.
  • Operator cluster: 3 extensions share same dev email; sibling count signals mass-produced wallpaper/newtab factory.
  • innerHTML DOM-XSS sink in popup.js with no CSP — content injection risk if API response is attacker-controlled.

Evidence

  • newtab_override manifest chrome_url_overrides.newtab set to newtab.html — replaces new-tab page.
  • uninstall_url_hijack crx setUninstallURL to https://gameograf.com/?utm_source=gameograf&utm_medium=link&utm_campaign=bg&utm_content=uninstall
  • install_url_hijack crx onInstalled opens https://gameograf.com/?utm_source=install&utm_medium=link&utm_campaign=bg&utm_content=install
  • privacy_policy_mismatch store Policy at haberikra.com (unrelated domain); scope_extension=false, data_collection=true, third_party_sharing=true.
  • operator_cluster api dev_email matches 3 extensions; compound fingerprint sibling_count=1; factory pattern.
  • dom_xss_sink crx innerHTML from variable in js/popup.js; no CSP present (MV3 but csp_present=false).
  • no_developer_name store developer_name is empty string; reduces accountability.
  • months_since_update store 15 months since last update — stale maintenance window for an active newtab extension.

Permissions Breakdown

  • search medium Allows modification of search provider; medium risk on its own.
  • host_permissions: https://api.gameograf.com/* low Scoped to developer-controlled API domain; limited blast radius.
  • chrome_url_overrides.newtab medium NewTab override replaces browser default; primary monetization vector for this category.

Pillar Scores

Permissions4.00
Reputation4.50
Network2.00
Webstore9.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-15 12:34
Listing SHA f6f9ebd86a9a…
Force block — not fired
Score recovered no
Elapsed