Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Anime JDM Wallpaper New Tab

hndiddblhijokmfbhmfgdmeeiddjnbme
Risk Score
4.27
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category NewTab
Installs 454
Rating 5.0
Last updated 2025-05-29 (16 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@gameograf.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Google's generic privacy policy used — does not scope data collection to this extension at all; admits 3rd-party sharing.
  • Uninstall AND install URL hijack to gameograf.com UTM links — monetization shell fingerprint.
  • Operator cluster: 20+ siblings under same dev email; mass NewTab publisher pattern.
  • New-tab override with search permission — broad reach into every browser session.
  • innerHTML sink in popup.js without CSP protection — DOM-XSS vector.

Evidence

  • privacy_policy_generic store PP URL is myaccount.google.com/privacypolicy — Google's own policy, scope_extension=false, data_collection=true, third_party_sharing=true.
  • uninstall_install_url_hijack crx Both onInstalled and uninstall URLs redirect to gameograf.com with UTM params — monetization shell.
  • operator_cluster_large api Dev email matches 20 extensions; compound fingerprint matches 4 siblings — mass NewTab publisher.
  • newtab_override manifest chrome_url_overrides.newtab = index.html replaces every new tab for all 454 users.
  • dom_xss_sink crx popup.js assigns innerHTML from variable with no CSP guard — DOM-XSS risk.
  • external_host_mlionltd_github_io crx js_external_hosts includes mlionltd.github.io — third-party GitHub Pages host, unrecognized owner.
  • maintenance_stale store 16 months since last update — falls in 12-24mo band (+6.0 maintenance score).
  • no_csp manifest content_security_policy is null; MV3 default applies but no explicit restriction, amplifies innerHTML risk.

Permissions Breakdown

  • search medium Allows reading and potentially overriding search provider; expected for NewTab but still elevates risk.
  • host_permissions: https://api.gameograf.com/* low Scoped to developer's own API domain; enables data exfil to first-party endpoint.
  • chrome_url_overrides.newtab medium Replaces every new tab — high-reach surface for monetization and search hijack.

Pillar Scores

Permissions3.00
Reputation5.50
Network2.00
Webstore8.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Operator Siblings (4)

Other extensions sharing this developer's compound fingerprint:

Bookkeeping

Rubric v3.6
Scored at 2026-09-16 04:51
Listing SHA 81fe651afb28…
Force block — not fired
Score recovered no
Elapsed