Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Porsche in nature Digital Art Aesthetic Live Wallpaper

cbeopjhnaopojodngbhkfonfkechifga
Risk Score
5.95
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category NewTab
Installs 67
Rating
Last updated 2026-06-16 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer birolkaya63536@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall AND install URL hijack to gameograf.com with UTM tracking — explicit monetization shell pattern.
  • NewTab override combined with 'search' permission enables full search-monetization replacement.
  • Privacy policy is Google's generic policy (scope_extension=false, data_collection=true, third_party_sharing=true) — worst-case under v3.5 rule D (+10.0).
  • Free-webmail developer (birolkaya63536@gmail.com), no verified publisher, no business domain — high reputation floor.
  • 6 external JS hosts including gameograf.com, Instagram, Netflix, YouTube, X.com contacted from a wallpaper extension.

Evidence

  • uninstall_url_hijack manifest chrome.runtime.setUninstallURL → gameograf.com with ovkas UTM params; explicit traffic-monetization signal.
  • install_url_hijack manifest onInstalled opens gameograf.com with identical UTM params; double install+uninstall hijack.
  • newtab_override manifest chrome_url_overrides.newtab = index.html; every new tab controlled by extension.
  • privacy_policy_generic store Policy is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • free_webmail_dev store birolkaya63536@gmail.com — numbered-alias free-webmail, no business website, no verified publisher.
  • js_external_hosts crx gameograf.com + www.google.com + www.instagram.com + www.netflix.com + www.youtube.com + x.com contacted.
  • webstore_monetization_cluster store NewTab+search+install/uninstall hijack to game portal = textbook monetization shell (+3+2+3+2=10 webstore).
  • csp_absent manifest content_security_policy is null; csp_present=false on MV3 extension with external host contacts.

Permissions Breakdown

  • search medium Allows manipulation of search provider; medium risk on its own but combined with newtab override is a monetization vector.
  • chrome_url_overrides.newtab high Replaces every new tab with extension-controlled page; primary mechanism for ad/affiliate monetization.

Pillar Scores

Permissions4.00
Reputation7.50
Network2.00
Webstore10.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 08:37
Listing SHA 307daac07ef9…
Force block — not fired
Score recovered no
Elapsed