Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Hinata’s Gentle Courage Live Wallpaper

caceifaleccakfgegklfgeganbpeopgi
Risk Score
5.62
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category NewTab
Installs 275
Rating 5.0
Last updated 2025-11-21 (10 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@gameograf.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • NewTab override with search permission — classic monetization shell replacing default new-tab page.
  • Privacy policy is Google's generic policy (scope_extension=false, data_collection=true, third_party_sharing=true) — admits data sharing without scoping to this extension.
  • Uninstall and install URL hijacks to gameograf.com tracking URLs — aggressive traffic monetization pattern.
  • No CSP declared (MV3) with innerHTML DOM-XSS sinks in popup.js and calendar.js — elevated XSS risk.
  • No developer name listed; verified publisher status doesn't offset opaque NewTab monetization structure.

Evidence

  • newtab_override manifest chrome_url_overrides.newtab set to newtab.html — replaces every new tab with extension content.
  • uninstall_url_hijack crx setUninstallURL to https://gameograf.com/?utm_source=gameograf&utm_medium=link&utm_campaign=bg&utm_content=uninstall
  • install_url_hijack crx onInstalled opens https://gameograf.com/?utm_source=install&utm_medium=link&utm_campaign=bg&utm_content=install
  • generic_privacy_policy api Privacy URL is Google's own privacy policy — scope_extension=false, admits data_collection and third_party_sharing.
  • dom_xss_sinks crx innerHTML assigned from variable in popup.js and calendar.js; no CSP to mitigate DOM-XSS.
  • no_developer_name store developer_name is empty string; identity accountability reduced despite verified_publisher=true.
  • no_csp manifest content_security_policy is null; MV3 provides defaults but no explicit CSP hardening declared.
  • verified_publisher store verified_publisher=true with resolving domain gameograf.com; mitigates some reputation risk.

Permissions Breakdown

  • search medium Allows modifying browser search behavior; relevant risk for a NewTab override extension.
  • host_permissions: https://api.gameograf.com/* low Scoped to developer's own API domain; narrow host access.
  • chrome_url_overrides.newtab medium Replaces new tab page — core monetization vector for wallpaper/NewTab shells.

Pillar Scores

Permissions5.00
Reputation5.50
Network2.00
Webstore8.00
Maintenance3.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 10:56
Listing SHA 57b078bc7099…
Force block — not fired
Score recovered no
Elapsed