Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Montreal Canadiens Dynamic New Tab Wallpapers

eamllpbephefnndpblbpnomcdpmomapa
Risk Score
5.73
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category NewTab
Installs 563
Rating 5.0
Last updated 2025-05-20 (16 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@gameograf.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • NewTab override + search permission enables ad-monetization on every new tab; uninstall/install URL hijack confirms monetization shape.
  • Privacy policy is Google's generic policy (scope_extension=false, data_collection=true, third_party_sharing=true) — scores maximum privacy risk.
  • bit.ly affiliate/cloaking hit in js_external_hosts; actual redirect destinations are opaque.
  • No CSP on MV3 extension; dom_sink_innerhtml_userctrl finding elevates XSS risk.
  • No developer name listed; dev_email dimension matches 10 sibling extensions by same operator fingerprint.

Evidence

  • uninstall_url_hijack + install_url_hijack manifest Both onInstalled and uninstall redirect to gameograf.com with UTM params — confirmed monetization shell.
  • chrome_url_overrides.newtab manifest Replaces new tab with index.html — every new tab is controlled by extension.
  • privacy_policy generic Google policy store Policy URL is myaccount.google.com/privacypolicy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • affiliate_hits: bit.ly crx bit.ly present in js_external_hosts — generic short-link redirector used for affiliate/cloaking.
  • dom_sink_innerhtml_userctrl crx popup.js assigns untrusted variable to innerHTML with no CSP guard — DOM-XSS risk.
  • no CSP declared (csp_present=false) manifest MV3 but no content_security_policy set; amplifies code-quality DOM-sink risk.
  • operator cluster: dev_email matches 10 extensions api info@gameograf.com associated with 10 extensions by dev_email dimension — fan-theme factory pattern.
  • no developer name store developer_name is empty string; reduces accountability signal.

Permissions Breakdown

  • search medium Allows overriding search behaviour; combined with NewTab override increases monetization risk.
  • host_permissions: https://api.gameograf.com/* low Scoped to developer's own API domain; limited blast radius.
  • chrome_url_overrides.newtab medium Replaces every new tab page — high-reach surface for ad injection or tracking.

Pillar Scores

Permissions4.00
Reputation6.00
Network2.50
Webstore8.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Operator Siblings (2)

Other extensions sharing this developer's compound fingerprint:

Bookkeeping

Rubric v3.6
Scored at 2026-09-15 13:19
Listing SHA d7892973ed96…
Force block — not fired
Score recovered no
Elapsed