Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Digital Gaze Live Wallpaper

dccgjjinkhjipbefmhpjkpelhgmfilnj
Risk Score
5.63
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category NewTab
Installs 553
Rating 4.0
Last updated 2025-10-21 (11 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@gameograf.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy URL returned HTTP error (fetch_error); policy unverifiable — scored as no policy (+10.0).
  • NewTab override with search permission and uninstall/install URL hijacks — classic monetization shell pattern.
  • Uninstall URL hijack redirects to gameograf.com with UTM tracking; install URL hijack also present.
  • No CSP declared (MV3, so no MV2 penalty, but innerHTML sinks lack mitigations).
  • Developer name field empty; no 'Offered by' display name reduces accountability.

Evidence

  • privacy_policy_fetch_failed api Privacy policy at gameograf.com/privacy-policy/ returned HTTPError; scored as fetched==false → +10.0 Privacy.
  • newtab_override manifest chrome_url_overrides.newtab = newtab.html; NewTab monetization pattern with search permission.
  • uninstall_url_hijack crx setUninstallURL to gameograf.com with UTM params; install redirect also present → +2.0+2.0 Webstore.
  • no_developer_name store developer_name is empty string; reduces accountability, +1.0 Reputation.
  • dom_sink_innerhtml crx Two innerHTML-from-variable sinks in popup.js and calendar.js; no CSP present → +2.0 Code Quality each capped.
  • verified_publisher store Extension has verified_publisher=true; -3.0 Reputation discount applied (floor 2.0).
  • cve_findings_empty api No CVEs found in bundled libs (jquery 3.7.1 is current/safe); CVE pillar = 0.0.
  • wayback_no_ownership_change api No ownership change detected; domain age 2051 days, not new; no bad host hits.

Permissions Breakdown

  • search medium Can modify search provider behavior; combined with newtab override increases monetization risk.
  • chrome_url_overrides.newtab medium Replaces new-tab page; primary monetization surface for this category of extension.
  • host_permissions: https://api.gameograf.com/* low Scoped to developer's own API domain; low blast radius but enables data exfiltration to dev.

Pillar Scores

Permissions5.00
Reputation4.00
Network2.00
Webstore7.50
Maintenance3.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-16 05:43
Listing SHA a64639a4f07a…
Force block — not fired
Score recovered no
Elapsed