Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Haeyong Razer RGB Room Live Wallpaper

gebkfjiglkikclehjbopccdcpkigiboc
Risk Score
5.68
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category NewTab
Installs 172
Rating 5.0
Last updated 2025-08-26 (13 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@gameograf.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's own policy (not scoped to this extension), admits data collection and 3rd-party sharing — effectively no real policy.
  • NewTab override combined with install/uninstall URL hijacks to gameograf.com — classic monetization shell pattern.
  • Two DOM-XSS innerHTML sinks (calendar.js, popup.js) with no CSP; amplifies DOM-XSS risk.
  • No developer name listed; no verified publisher badge; accountability gap.
  • Install and uninstall URL hijacks redirect users to developer site with UTM tracking parameters.

Evidence

  • newtab_override manifest chrome_url_overrides.newtab set to newtab.html — replaces every new tab with developer-controlled page.
  • install_uninstall_hijack manifest Both install and uninstall URLs redirect to gameograf.com with UTM params — monetization funnel.
  • generic_privacy_policy store Policy URL is Google's own privacy policy (myaccount.google.com); scope_extension=false, data_collection=true, third_party_sharing=true.
  • dom_xss_sink_no_csp crx innerHTML sinks in calendar.js and popup.js; csp_present=false increases exploitability.
  • no_developer_name store developer_name is empty string; no 'Offered by' identity; accountability gap.
  • maintenance_stale store months_since_update=13; falls in 12-24mo band (+6.0 maintenance).
  • no_csp manifest content_security_policy is null; MV3 has strict defaults but no explicit CSP declared.
  • js_external_hosts_broad crx 12 external JS hosts including Google services and youtube.com; >3 distinct registrable domains.

Permissions Breakdown

  • search medium Allows reading and manipulating search queries; medium risk for a NewTab extension.
  • host_permissions: https://api.gameograf.com/* low Scoped to developer's own API domain; limited blast radius.
  • chrome_url_overrides.newtab medium Replaces new-tab page; high-visibility monetization surface, ad-tech injection risk.

Pillar Scores

Permissions4.00
Reputation6.50
Network2.00
Webstore8.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 11:18
Listing SHA 299825ec80bf…
Force block — not fired
Score recovered no
Elapsed