Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Satoru Gojo Live Wallpaper

eijkngjjiekdphnmbdhmidihbfgaggel
Risk Score
5.93
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category NewTab
Installs 98
Rating
Last updated 2026-05-03 (4 months ago)
Manifest version MV3
CSP present ❌ no
Developer halilseker3455@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall and install URL both hijacked to gameograf.com ad-tracking URL — clear monetization shell pattern.
  • New-tab override + search permission with free-webmail dev, no developer name — anonymous operator.
  • Privacy policy is generic Google account policy (scope_extension=false, admits data collection + 3rd-party sharing) — worse than no policy.
  • Extension contacts gameograf.com, instagram.com, netflix.com, youtube.com, x.com — broad external reach for a wallpaper.
  • Verified publisher badge does not offset anonymous dev identity or monetization indicators per v3.5 invariant 0c/E.

Evidence

  • install_url_hijack + uninstall_url_hijack manifest Both install and uninstall redirect to gameograf.com with utm tracking params — monetization shell pattern (+2.0+3.0 webstore).
  • newtab_override manifest chrome_url_overrides.newtab=index.html replaces every new tab, combined with search permission.
  • generic_google_privacy_policy store Privacy URL is myaccount.google.com/privacypolicy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 D).
  • free_webmail_dev_no_name store Developer email halilseker3455@gmail.com, developer_name empty; free-webmail + no name → reputation floor 7.5.
  • js_external_hosts_broad crx Extension references gameograf.com, instagram.com, netflix.com, youtube.com, x.com — 6 external hosts for a wallpaper extension.
  • verified_publisher_monetization_cap store verified_publisher=true but monetization shell (install/uninstall hijack to ad-tracker) caps discount to -1.0 per v3.5 invariant E.
  • new_tab_override_monetization manifest NewTab override with gameograf.com monetization pattern scores +2.0 webstore (new-tab override with monetization shape).
  • cve_findings_raw_empty crx No CVEs detected; jquery 3.7.1 is current — CVE pillar 0.0.

Permissions Breakdown

  • search medium Can manipulate search provider behavior; medium risk when paired with newtab override.
  • chrome_url_overrides.newtab high Replaces new tab page; high monetization surface, captures all new-tab navigations.

Pillar Scores

Permissions5.00
Reputation7.50
Network0.00
Webstore10.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 04:53
Listing SHA 10b1b5ae90d7…
Force block — not fired
Score recovered no
Elapsed