Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Web Risk Scanner

geidphfhgbhcmlnnmpadjacpcnlgoffc
Risk Score
5.37
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Security
Installs 16
Rating 5.0
Last updated 2026-03-23 (6 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@ovkas.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall AND install URL hijack both redirect to gameograf.com ad/UTM URL — classic monetization shell pattern.
  • Privacy policy URL returns HTTP error (fetch_error) — effectively no accessible privacy policy for a broad-host extension.
  • Broad content scripts on all HTTP/HTTPS pages with no CSP and no observable function — extreme capability for 16-install 'security' tool.
  • No developer name listed; 'Web Risk Scanner' category framing contradicted by gameograf.com redirect infrastructure.
  • small_install_high_perm anomaly (16 installs + broad host access) raises tail-attack-surface concern.

Evidence

  • uninstall_url_hijack crx setUninstallURL → gameograf.com with UTM params (ovkas); 3.0pt Webstore penalty applied.
  • install_url_hijack crx onInstalled opens gameograf.com with UTM params; +2.0pt Webstore penalty applied.
  • privacy_policy_fetch_error api privacy_policy_classification.fetched==false (HTTPError); Privacy pillar scored 10.0.
  • broad_host_permissions manifest host_permissions + content_scripts both match http://* and https://*; all-site read/write capability.
  • js_external_hosts crx gameograf.com listed as external JS host; same domain as install/uninstall hijack target.
  • install_perm_anomaly store small_install_high_perm==true: 16 installs with HIGH host permissions flagged.
  • no_developer_name store developer_name is empty string; anonymous publisher despite verified_publisher==true.
  • verified_publisher store verified_publisher==true but monetization redirect infrastructure (gameograf.com) triggers invariant 0c cap at -1.0.

Permissions Breakdown

  • tabs medium Access to tab URLs and metadata; moderate risk for a security scanner.
  • storage low Local data persistence only; low intrinsic risk.
  • http://*/* high Broad host access over all HTTP sites enables content interception on every page.
  • https://*/* high Broad host access over all HTTPS sites; combined with content scripts = full page read on every site.

Pillar Scores

Permissions5.50
Reputation5.50
Network2.00
Webstore8.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 07:06
Listing SHA ed09ceac64d0…
Force block — not fired
Score recovered no
Elapsed