Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Luffy Moonlight Meditation Live Wallpaper

gafbkkfalgndkoilabfhmjjjgeihboed
Risk Score
6.20
Risk Level: High
Recommendation: 🚫 BLOCK
Category NewTab
Installs 340
Rating
Last updated 2025-06-03 (15 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@gameograf.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • NewTab override by a 13-sibling operator cluster strongly suggests ad-monetization shell pattern.
  • Privacy policy URL returns fetch error — effectively no accessible privacy disclosure for users.
  • Uninstall and install URL hijacks redirect users to developer site with tracking parameters.
  • Large sibling cluster (31 by dev_email, 50 by install_url) indicates factory-produced extension operation.
  • innerHTML DOM-XSS sink in popup.js with no CSP increases exploit surface.

Evidence

  • newtab_override manifest chrome_url_overrides.newtab set to newtab.html — every new tab replaced.
  • operator_cluster api 13 compound siblings, 31 by dev_email, 50 by install_url — factory shell operation.
  • uninstall_url_hijack crx setUninstallURL targets gameograf.com with UTM tracking on uninstall.
  • install_url_hijack crx onInstalled opens gameograf.com with UTM tracking params.
  • privacy_policy_fetch_error api privacy_policy_classification.fetched==false due to HTTPError; policy inaccessible.
  • dom_sink_innerhtml_userctrl crx js/popup.js assigns user-controlled variable to innerHTML without CSP guard.
  • no_csp manifest content_security_policy is null; MV3 default applies but no custom hardening.
  • stale_update store 15 months since last update — falls in 12–24mo band (+6.0 maintenance).

Permissions Breakdown

  • search medium Allows querying browser search; paired with newtab override this enables search provider manipulation.
  • chrome_url_overrides.newtab high Replaces every new tab — high-reach surface for ad-monetization and search hijack.
  • host_permissions: https://api.gameograf.com/* low Scoped to developer's own API domain; limited blast radius.

Pillar Scores

Permissions4.00
Reputation4.00
Network2.00
Webstore10.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-16 07:38
Listing SHA 4d1a8df1a253…
Force block — not fired
Score recovered no
Elapsed