Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Call Of Duty Warzone Live Wallpaper

dbmphmppekeklghdhehpnflagiiifflh
Risk Score
5.72
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category NewTab
Installs 260
Rating 5.0
Last updated 2025-06-02 (15 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@gameograf.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • NewTab override with search override — classic ad-monetization shell; uninstall and install URL hijacks confirmed.
  • Privacy policy is Google's generic policy (scope_extension=false, data_collection=true, third_party_sharing=true) — worst-case Privacy score.
  • No CSP (csp_present=false) and dom_sink_innerhtml_userctrl in popup.js raises DOM-XSS risk.
  • Uninstall and install URL hijacks redirect to gameograf.com with UTM tracking parameters.
  • 15 months since update; newtab+search combo with no developer name listed raises monetization-shell concern.

Evidence

  • newtab_override manifest chrome_url_overrides.newtab set to newtab.html; combined with 'search' permission = search monetization vector.
  • uninstall_url_hijack crx setUninstallURL targets https://gameograf.com/?utm_source=gameograf&utm_medium=link&utm_campaign=bg&utm_content=uninstall
  • install_url_hijack crx onInstalled opens https://gameograf.com/?utm_source=install&utm_medium=link&utm_campaign=bg&utm_content=install
  • generic_privacy_policy store Policy URL is Google's own privacy policy (myaccount.google.com); scope_extension=false, data_collection=true, third_party_sharing=true.
  • no_csp manifest content_security_policy is null; dom_sink_innerhtml_userctrl found in popup.js — DOM-XSS risk unmitigated.
  • no_developer_name store developer_name is empty string; verified_publisher=true but no display name reduces accountability.
  • stale_extension store 15 months since last update; newtab monetization shell with no CSP and generic privacy policy.
  • verified_publisher_cap store verified_publisher=true but months_since_update=15 (>12) triggers invariant 0c discount cap at -1.0.

Permissions Breakdown

  • search medium Allows overriding search provider; medium risk on its own but paired with newtab override raises concern.
  • host_permissions: https://api.gameograf.com/* low Scoped to developer's own API domain only; limited blast radius.
  • chrome_url_overrides.newtab high Replaces new-tab page; primary vector for search monetization and ad injection.

Pillar Scores

Permissions5.00
Reputation5.50
Network2.00
Webstore8.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 06:17
Listing SHA 7abb06c92a91…
Force block — not fired
Score recovered no
Elapsed