Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

D. Luffy Live Wallpaper

ehhblemfpifkffhgbpekenedademifoe
Risk Score
6.17
Risk Level: High
Recommendation: 🚫 BLOCK
Category NewTab
Installs 157
Rating
Last updated 2026-05-03 (4 months ago)
Manifest version MV3
CSP present ❌ no
Developer halilseker3455@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall and install URL both hijacked to gameograf.com — classic traffic-monetization shell pattern.
  • New tab override replaces browser new-tab page — primary ad-monetization surface.
  • Privacy policy is generic Google account policy; admits data collection & 3rd-party sharing with no extension scope.
  • Free-webmail developer, empty developer name, no business domain — unverifiable identity.
  • External JS contacts affiliate-flavored gameograf.com domain with UTM tracking params.

Evidence

  • uninstall_url_hijack crx chrome.runtime.setUninstallURL → https://gameograf.com/?utm_source=ovkas — 3rd-party affiliate redirect on uninstall.
  • install_url_hijack crx onInstalled opens https://gameograf.com/?utm_source=ovkas — 3rd-party page opened on install.
  • newtab_override manifest chrome_url_overrides.newtab = index.html; monetization shell pattern for wallpaper/NewTab category.
  • privacy_policy_generic store Policy is Google account policy (scope_extension=false, data_collection=true, third_party_sharing=true) — +10.0 privacy.
  • developer_identity store Developer name empty, email is free Gmail (halilseker3455@gmail.com), no business domain — elevated reputation risk.
  • js_external_hosts crx gameograf.com plus google/instagram/netflix/youtube/x.com referenced in JS; gameograf carries UTM affiliate params.
  • verified_publisher store Verified publisher badge present; applies -3.0 to reputation but capped at -1.0 due to monetization signals (v3.5 rule E).
  • csp_absent manifest content_security_policy is null; MV3 has strict default so no +2.0 penalty, but no CSP declared explicitly.

Permissions Breakdown

  • search medium Allows overriding search provider; medium risk in context of NewTab override.
  • chrome_url_overrides.newtab high Replaces new tab page — core monetization surface for traffic hijacking.

Pillar Scores

Permissions4.00
Reputation7.00
Network2.00
Webstore10.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 13:43
Listing SHA f1de61480ddd…
Force block — not fired
Score recovered no
Elapsed