Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Kansas City Chiefs Wallpaper

dchcijfinmfkdjfidfcegkmfpiilklea
Risk Score
3.92
Risk Level: Low
Recommendation: 🚫 BLOCK
Category NewTab
Installs 178
Rating 5.0
Last updated 2026-06-25 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer orhanyildizsd@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall URL hijack to owhit.com — classic monetization shell signal
  • Install URL hijack to owhit.com — tracks installs for third-party attribution
  • NewTab override combined with search permission enables search monetization
  • Privacy policy is generic Google account policy, not scoped to this extension at all
  • Free-webmail gmail developer with no verified business identity

Evidence

  • uninstall_url_hijack crx chrome.runtime.setUninstallURL points to https://owhit.com/uninstall — third-party tracking.
  • install_url_hijack crx onInstalled opens https://owhit.com/kansas-city-chiefs-wallpaper — third-party attribution.
  • newtab_override manifest chrome_url_overrides.newtab = index.html replaces every new-tab for all users.
  • generic_privacy_policy store Policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • free_webmail_developer store Developer email orhanyildizsd@gmail.com; no verified publisher badge; no business domain.
  • js_external_hosts crx Extension references chatgpt.com, instagram.com, netflix.com, x.com, youtube.com — unrelated to wallpaper function.
  • new_tab_monetization_shape manifest NewTab + search permission + owhit.com hijacks = classic ad-monetization aggregator pattern.
  • csp_absent manifest content_security_policy is null; csp_present=false on MV3 extension.

Permissions Breakdown

  • search medium Allows reading/overriding search queries; medium risk for a NewTab extension.
  • chrome_url_overrides.newtab high Replaces every new-tab page with developer-controlled content; high monetization risk.

Pillar Scores

Permissions5.00
Reputation7.50
Network2.00
Webstore9.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 04:06
Listing SHA 8823e2a33d00…
Force block — not fired
Score recovered no
Elapsed