Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Sanrio Cinnamoroll Halloween Live Wallpaper

cbkaacjfboiijjkojeodihmpldbjndbp
Risk Score
3.45
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category NewTab
Installs 72
Rating
Last updated 2026-05-12 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@gameograf.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • NewTab override with uninstall+install URL hijacks — classic monetization shell pattern scoring +2+2+2 in Webstore.
  • No CSP (csp_present=false, MV3) — two innerHTML DOM-XSS sinks in popup.js and calendar.js lack any mitigation.
  • Search permission combined with newtab override enables query interception and search monetization.
  • Verified publisher but no developer name listed; 72 installs with 0 ratings reduces trust signal value.
  • Privacy policy is scoped and adequate, but extension contacts 12 external JS hosts including openai.com and gstatic.com.

Evidence

  • newtab_override manifest chrome_url_overrides.newtab = newtab.html; replaces new-tab page — primary monetization surface.
  • uninstall_url_hijack crx setUninstallURL targets https://gameograf.com/?utm_source=extension&utm_medium=install (3rd-party).
  • install_url_hijack crx onInstalled opens https://gameograf.com/?utm_source=extension&utm_medium=install.
  • no_csp manifest content_security_policy is null; MV3 default strict CSP applies but csp_present=false in scan.
  • dom_xss_sinks crx innerHTML from variable in js/popup.js and js/calendar.js — XSS risk without CSP.
  • verified_publisher store verified_publisher=true; discounts Reputation but no developer name provided.
  • external_hosts crx 12 external JS hosts including chat.openai.com, ssl.gstatic.com, multiple Google services.
  • privacy_policy_adequate api Policy fetched; scope_extension=true, data_collection=true, retention=true, third_party_sharing=true.

Permissions Breakdown

  • search medium Allows reading/manipulating search queries; concerning in a NewTab override context.
  • host_permissions: https://api.gameograf.com/* low Scoped to developer-controlled API domain; matches stated wallpaper/data function.
  • chrome_url_overrides.newtab medium Replaces new-tab page — primary monetization surface for this category.

Pillar Scores

Permissions3.50
Reputation4.00
Network2.50
Webstore7.00
Maintenance0.00
Privacy0.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 10:58
Listing SHA 62fe8130b0c6…
Force block — not fired
Score recovered no
Elapsed