Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Captivating Artistic XXXTentacion Live Wallpaper

gjjmhehfmcimpgldcnbcjcmpjlabjkhf
Risk Score
6.26
Risk Level: High
Recommendation: 🚫 BLOCK
Category NewTab
Installs
Rating
Last updated 2026-06-21 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer halilseker3455@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall URL hijack routes to gameograf.com ad-tracking URL with UTM params — confirmed monetization shell.
  • Install URL hijack also redirects to gameograf.com on install — aggressive traffic monetization.
  • Privacy policy is Google's generic account policy (scope_extension=false, admits data collection + 3rd-party sharing) — scores 10.0.
  • NewTab override + 'search' permission = classic search-monetization pattern; extension contacts Google, YouTube, Netflix, Instagram, X.
  • Free-webmail developer (gmail), no verified publisher, no business domain — unaccountable operator.

Evidence

  • uninstall_url_hijack manifest chrome.runtime.setUninstallURL to gameograf.com with ovkas UTM params — monetization shell confirmed.
  • install_url_hijack manifest onInstalled opens gameograf.com with UTM tracking — aggressive install-time redirect.
  • newtab_override manifest chrome_url_overrides.newtab = index.html; search permission also declared — full newtab monetization pattern.
  • privacy_policy_generic store Policy is Google account policy: scope_extension=false, data_collection=true, third_party_sharing=true — worst-case privacy score.
  • js_external_hosts crx Contacts gameograf.com, google.com, instagram.com, netflix.com, youtube.com, x.com — 5 unrelated major platforms.
  • free_webmail_dev store Developer halilseker3455@gmail.com — gmail, no business website, no verified publisher badge.
  • numbered_alias_email store Email halilseker3455@gmail.com contains numeric suffix — pattern associated with throwaway operator accounts.
  • no_csp manifest content_security_policy is null on MV3 extension — no CSP declared.

Permissions Breakdown

  • search medium Allows overriding search provider; paired with newtab override = monetization vector.
  • chrome_url_overrides.newtab high Replaces new-tab page; classic adware/monetization shell pattern with search redirect capability.

Pillar Scores

Permissions5.00
Reputation7.50
Network2.50
Webstore10.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 14:07
Listing SHA 595ec2145b86…
Force block — not fired
Score recovered no
Elapsed