Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Lilo & Stitch Elvis Style Live Wallpaper

hknohgfkdplfanfeaoeenibilkllofcd
Risk Score
6.33
Risk Level: High
Recommendation: 🚫 BLOCK
Category NewTab
Installs 110
Rating
Last updated 2026-05-05 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer donaldtirpan@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall AND install URL both hijack to gameograf.com ad-tracking endpoint — classic traffic-monetization shell.
  • Privacy policy is Google's own policy (not scoped to this extension) AND admits data collection + third-party sharing → +10 privacy.
  • NewTab override + search permission = search-hijack surface; free-webmail dev with no developer name.
  • Extension contacts six JS external hosts (gameograf.com, Google, Instagram, Netflix, YouTube, X) from a wallpaper/NewTab.
  • Verified-publisher badge does not justify newtab+search override combo; discount capped per capability-gate rule.

Evidence

  • install_url_hijack manifest onInstalled opens gameograf.com with UTM tracking params — monetization shell pattern (+2.0 webstore).
  • uninstall_url_hijack manifest setUninstallURL points to gameograf.com UTM endpoint — explicit traffic monetization indicator (+3.0 webstore).
  • newtab_override manifest chrome_url_overrides.newtab present; replaces every new tab — core monetization surface (+2.0 permissions).
  • privacy_policy_generic store Policy URL is Google's global policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5-D).
  • js_external_hosts crx 6 external JS hosts: gameograf.com, google.com, instagram.com, netflix.com, youtube.com, x.com — broad reach from wallpaper.
  • free_webmail_no_dev_name store Developer email is gmail.com; developer_name is empty — anonymous publisher with free webmail.
  • verified_publisher_capability_gate store verified_publisher=true but capability gate applies (newtab+search override); discount capped to -1.0 per v2 rule 0b.
  • cve_findings_raw_empty crx No CVEs found; jquery 3.7.1 is current and unaffected. CVE pillar = 0.

Permissions Breakdown

  • search medium Allows overriding search provider; combined with newtab override this is a classic search-hijack surface.
  • chrome_url_overrides.newtab high Replaces every new tab with extension page; primary monetization vector for traffic-monetization shells.

Pillar Scores

Permissions5.00
Reputation7.50
Network4.00
Webstore10.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 05:11
Listing SHA f76e7bd1a1d3…
Force block — not fired
Score recovered no
Elapsed