Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Hello Kitty Live Wallpaper

glbkljkmeeaplefecfhkekgplnhollbf
Risk Score
5.61
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category NewTab
Installs 507
Rating 5.0
Last updated 2025-11-21 (10 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@gameograf.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • NewTab override with install/uninstall URL hijack to gameograf.com — clear monetization shell pattern.
  • Privacy policy is Google's own policy (scope_extension=false, data_collection=true, third_party_sharing=true) — not scoped to this extension.
  • No developer name provided despite verified_publisher status; blank manifest name/description (__MSG__ keys only).
  • Two innerHTML DOM-XSS sinks with no CSP present, elevating XSS exploitability.
  • Uninstall and install URL hijack both redirect to gameograf.com UTM-tracked pages — monetization/tracking intent.

Evidence

  • newtab_override_with_monetization manifest chrome_url_overrides.newtab set; uninstall_url_hijack and install_url_hijack both redirect to gameograf.com with UTM params.
  • privacy_policy_generic_google store Privacy URL is Google's own policy (myaccount.google.com/privacypolicy); scope_extension=false, data_collection=true, third_party_sharing=true.
  • dom_xss_no_csp crx Two innerHTML sinks in popup.js and calendar.js; csp_present=false, no content_security_policy declared.
  • developer_name_missing store developer_name is empty string despite verified_publisher=true and is_featured_by_google=true.
  • install_uninstall_url_hijack manifest Both onInstalled and setUninstallURL point to third-party gameograf.com with campaign tracking parameters.
  • verified_publisher_featured store Extension is verified_publisher and featured by Google, partially mitigating reputation risk but not monetization concerns.
  • operator_cluster_singleton api sibling_count=0; no other extensions share this fingerprint cluster.
  • cve_findings_empty crx No CVEs found; jquery 3.7.1 is current and unaffected.

Permissions Breakdown

  • search medium Search override capability; medium risk on its own but combined with newtab override amplifies control.
  • host_permissions: https://api.gameograf.com/* low Scoped to developer's own API domain; low blast radius.
  • chrome_url_overrides.newtab medium Replaces every new tab with extension page; persistent high-frequency surface for monetization or tracking.

Pillar Scores

Permissions5.50
Reputation4.00
Network2.00
Webstore8.50
Maintenance3.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 11:12
Listing SHA a78fee98743b…
Force block — not fired
Score recovered no
Elapsed