Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Candy Match Saga Gameograf

gjocodejhekfnbfbpdfidobgbbacmgma
Risk Score
4.48
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 61
Rating
Last updated 2024-12-27 (21 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@gameograf.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall and install URL hijacks both present — classic traffic-monetization shell pattern even with null targets.
  • Privacy policy is Google's generic account policy, not scoped to this extension; fetched=true but scope_extension=false with data_collection=true and third_party_sharing=true — worst-case privacy score.
  • Developer name empty; no 'Offered by' attribution despite verified_publisher flag.
  • Extension is 21 months stale (6–24mo band) with only 61 installs — low-accountability asset.
  • External JS hosts (gameograf.com, www.play.gameograf.com) contacted but no CSP present, creating remote-code-load surface.

Evidence

  • install_url_hijack + uninstall_url_hijack crx Both install and uninstall URL hijacks flagged true; targets null but hooks registered — monetization/traffic-capture pattern.
  • privacy_policy_generic_google store Policy URL is myaccount.google.com/privacypolicy — Google's own account policy, not the developer's, not scoped to this extension.
  • privacy_classification_bad api fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → v3.5 rule D: +10.0 privacy.
  • developer_name_empty store developer_name is empty string; no 'Offered by' visible despite verified_publisher=true.
  • js_external_hosts_no_csp crx Extension contacts gameograf.com and www.play.gameograf.com but csp_present=false; remote resource load uncontrolled.
  • months_since_update_21 store Last updated Dec 2024; 21 months stale — falls in 6–24mo band (+6.0 maintenance).
  • no_developer_name store No developer display name; reputation start 5.0 +1.0 (no 'Offered by') = 6.0, then -3.0 verified_publisher → 3.0, floor at 2.0 but adjusted to 4.5 with stale cap.
  • verified_publisher_stale_cap store verified_publisher=true but months_since_update=21 >18 → invariant 0c caps discount at -1.0, not -3.0.

Pillar Scores

Permissions0.00
Reputation4.50
Network0.00
Webstore8.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 04:50
Listing SHA b37202565c24…
Force block — not fired
Score recovered no
Elapsed