Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Nissan Skyline GT-R R34 Live Wallpaper

fjigogdcnnemnojaanbmdmkbbhgmfdaa
Risk Score
5.64
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category NewTab
Installs 230
Rating
Last updated 2025-09-24 (12 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@gameograf.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy — not scoped to this extension; admits data collection and 3rd-party sharing.
  • NewTab override + install/uninstall URL hijack to gameograf.com — clear traffic-monetization shell pattern.
  • Developer name is blank; no 'Offered by' identity despite verified_publisher claim.
  • DOM-XSS sinks (innerHTML from variables) in calendar.js and popup.js with no CSP in place.
  • Uninstall URL hijack redirects users to developer site with UTM tracking on removal.

Evidence

  • newtab_override manifest chrome_url_overrides.newtab set to newtab.html — replaces every new tab with developer-controlled page.
  • uninstall_url_hijack crx setUninstallURL targets https://gameograf.com/?utm_source=gameograf&utm_medium=link&utm_campaign=bg.
  • install_url_hijack crx onInstalled opens https://gameograf.com/?utm_source=install — monetization redirect on install.
  • generic_privacy_policy store Policy URL is Google's own privacy policy (myaccount.google.com); scope_extension=false, data_collection=true, third_party_sharing=true.
  • no_developer_name store developer_name is empty string; no 'Offered by' identity visible despite verified_publisher=true.
  • dom_xss_no_csp crx Two innerHTML-from-variable sinks in calendar.js and popup.js; csp_present=false amplifies XSS risk.
  • js_external_hosts_broad crx 12 external JS hosts referenced including Google properties and youtube.com beyond stated wallpaper function.
  • maintenance_stale api months_since_update=12 (6–12mo band); install count only 230 — low adoption, moderate staleness.

Permissions Breakdown

  • search medium Allows modification of search provider; NewTab override amplifies search monetization risk.
  • chrome_url_overrides.newtab high Replaces new-tab page; primary vector for traffic/ad monetization in wallpaper shells.
  • host_permissions: https://api.gameograf.com/* medium Outbound calls to developer's own API; scoped but enables data exfiltration to dev server.

Pillar Scores

Permissions5.00
Reputation5.50
Network2.50
Webstore7.50
Maintenance3.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 11:51
Listing SHA d19fff78ccb6…
Force block — not fired
Score recovered no
Elapsed