Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Sabrina Carpenter Wallpapers Gameograf

gimhgipihjkolgkmpffjccnlljanjdcd
Risk Score
6.04
Risk Level: High
Recommendation: 🚫 BLOCK
Category NewTab
Installs 1,000
Rating 4.8
Last updated 2025-05-29 (16 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@gameograf.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's own policy — not scoped to this extension, admits data collection and 3rd-party sharing: scores 10.0.
  • NewTab override + uninstall/install URL hijacks to gameograf.com confirm monetization shell pattern.
  • Operator cluster: 8 sibling extensions under same dev email, clear factory pattern.
  • Privacy policy URL points to Google's policy (scope_extension=false, data_collection=true, third_party_sharing=true) — worst-case generic policy.
  • months_since_update=16 with NewTab override creates stale high-reach surface; mlionltd.github.io is an opaque external JS host.

Evidence

  • newtab_override_monetization manifest chrome_url_overrides.newtab set to index.html; install+uninstall URL hijacks both redirect to gameograf.com UTM links.
  • privacy_policy_generic_google store Privacy URL is myaccount.google.com/privacypolicy — Google's own policy, scope_extension=false, data_collection=true, third_party_sharing=true.
  • operator_cluster_siblings api dev_email matches 8 sibling extensions; compound fingerprint sibling_count=1 (hpckfgjkocoodghiifpiijpechoimilk).
  • uninstall_url_hijack crx chrome.runtime.setUninstallURL → https://gameograf.com/?utm_source=uninstall — confirmed 3rd-party redirect.
  • install_url_hijack crx onInstalled opens https://gameograf.com/?utm_source=install — confirmed install-time redirect.
  • external_js_host_opaque crx js_external_hosts includes mlionltd.github.io — unrelated GitHub Pages domain, not developer-controlled.
  • dom_xss_sink crx innerHTML assigned from variable in js/popup.js with csp_present=false — DOM-XSS risk.
  • stale_newtab store months_since_update=16 on a NewTab extension with no CSP and external JS host.

Permissions Breakdown

  • search medium Allows reading/overriding search queries; combined with NewTab override amplifies search monetization risk.
  • host_permission: https://api.gameograf.com/* low Scoped to developer's own API domain; limited blast radius but enables data exfil to operator.
  • chrome_url_overrides.newtab medium Replaces every new tab — high reach, standard monetization vector for wallpaper/NewTab shells.

Pillar Scores

Permissions3.00
Reputation5.50
Network3.00
Webstore8.50
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Operator Siblings (4)

Other extensions sharing this developer's compound fingerprint:

Bookkeeping

Rubric v3.6
Scored at 2026-09-15 13:10
Listing SHA 3d07d41b017d…
Force block — not fired
Score recovered no
Elapsed