Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Ford Mustang GT

fnacoipijgokcaaboikjnlonhnfcjgpi
Risk Score
6.02
Risk Level: High
Recommendation: 🚫 BLOCK
Category NewTab
Installs 1,000
Rating 5.0
Last updated 2025-05-14 (15 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@haberikra.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • NewTab override with install+uninstall URL hijacks to haberikra.com — classic monetization shell pattern.
  • Privacy policy is Google's generic account policy, entirely unscoped to this extension, while data_collection and third_party_sharing are true.
  • Uninstall URL hijack sends user to haberikra.com with UTM tracking on extension removal.
  • Install URL hijack opens haberikra.com immediately on install — onInstalled monetization.
  • No developer name listed; months_since_update=15 with newtab override raises abandoned-monetization risk.

Evidence

  • newtab_override manifest chrome_url_overrides.newtab set to newtab.html — replaces every new tab for all users.
  • uninstall_url_hijack crx setUninstallURL targets https://haberikra.com/?utm_source=gameograf&utm_medium=link&utm_campaign=bg&utm_content=uninstall
  • install_url_hijack crx onInstalled opens https://haberikra.com/?utm_source=install&utm_medium=link&utm_campaign=bg&utm_content=install
  • generic_privacy_policy store Privacy policy URL is Google's account policy (myaccount.google.com); scope_extension=false, data_collection=true, third_party_sharing=true.
  • no_developer_name store developer_name is empty string; verified_publisher=true but no visible 'Offered by' name.
  • dom_xss_sink crx js/popup.js uses innerHTML from variable without sanitization — DOM-XSS risk.
  • stale_newtab_monetization store 15 months since last update; newtab shell with UTM-tracked install/uninstall hooks to haberikra.com.
  • no_csp manifest content_security_policy is null (csp_present=false); MV3 default applies but no explicit policy.

Permissions Breakdown

  • search medium Allows search provider override; medium risk on its own.
  • host_permission: https://api.gameograf.com/* medium Scoped to single third-party domain; enables data exfil to gameograf.com.
  • chrome_url_overrides.newtab medium Replaces new-tab page; high-visibility monetization surface.

Pillar Scores

Permissions4.00
Reputation6.00
Network2.00
Webstore8.50
Maintenance6.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 08:28
Listing SHA 35ffbbc15e95…
Force block — not fired
Score recovered no
Elapsed