Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Ryu vs. Ken Street Fighter Aduket

figaecccpniojljggfecelnfkgohecoj
Risk Score
5.72
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category NewTab
Installs 69
Rating
Last updated 2025-06-06 (15 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@gameograf.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • NewTab override with search permission — classic search-monetization shell; uninstall and install URL hijacks to gameograf.com confirm monetization intent.
  • Privacy policy is Google's generic account policy (scope_extension=false, data_collection=true, third_party_sharing=true) — admits data collection with no extension-specific scope.
  • Uninstall URL hijack to gameograf.com tracking UTM and install URL hijack both confirmed — aggressive user tracking.
  • No developer name listed; verified publisher status partially mitigated but 15-month stale update triggers invariant 0c cap on discount.
  • DOM-XSS sink (innerHTML) in popup.js with no CSP present — low exploitability given no external user input, but increases risk if compromised.

Evidence

  • newtab_override manifest chrome_url_overrides.newtab set to newtab.html — replaces new-tab page for all users.
  • uninstall_url_hijack crx setUninstallURL points to https://gameograf.com/?utm_source=gameograf&utm_medium=link&utm_campaign=bg&utm_content=uninstall
  • install_url_hijack crx onInstalled opens https://gameograf.com/?utm_source=install&utm_medium=link&utm_campaign=bg&utm_content=install
  • generic_privacy_policy store Privacy policy URL is Google's account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • no_csp manifest content_security_policy is null; csp_present=false on MV3 extension with innerHTML sink.
  • dom_xss_sink crx js/popup.js uses innerHTML assignment from variable — DOM-XSS sink without CSP protection.
  • stale_update store Last updated June 2025; months_since_update=15, triggering 6-12mo maintenance band and 0c cap on VP discount.
  • no_developer_name store developer_name is empty string; reduces accountability despite verified_publisher=true.

Permissions Breakdown

  • search medium Allows modifying search settings; combined with newtab override is a monetization vector.
  • chrome_url_overrides.newtab medium Replaces new-tab page; standard shell pattern for search monetization.
  • host_permissions: https://api.gameograf.com/* low Scoped to developer's own API domain; limited reach.

Pillar Scores

Permissions4.00
Reputation4.50
Network2.00
Webstore8.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 12:03
Listing SHA e64bcc1abddf…
Force block — not fired
Score recovered no
Elapsed