Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Sonic Live Wallpaper

hohjghigkopoaedmhchngifegbieigmh
Risk Score
5.54
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category NewTab
Installs 2,000
Rating 4.7
Last updated 2025-06-10 (15 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@gameograf.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy URL unreachable (fetch error) — effectively no privacy disclosure.
  • NewTab override hijacks every new tab; both install and uninstall URL hijacks to gameograf.com ad tracking.
  • Privacy policy domain (haberikra.com) differs from developer domain (gameograf.com) — suspicious mismatch.
  • Stale update (15 months) with newtab override increases ongoing risk window.
  • innerHTML DOM-XSS sink in popup.js with no CSP — content injection risk.

Evidence

  • newtab_override manifest chrome_url_overrides.newtab = newtab.html; replaces every new tab for all users.
  • uninstall_url_hijack crx setUninstallURL → https://gameograf.com/?utm_source=gameograf&utm_medium=link&utm_campaign=bg
  • install_url_hijack crx onInstalled opens https://gameograf.com/?utm_source=install — 3rd-party tracking on install.
  • privacy_policy_fetch_failed api Privacy policy at haberikra.com/privacy-policy/ returned HTTPError; treated as no policy.
  • privacy_policy_domain_mismatch store Dev email domain gameograf.com; privacy policy hosted on unrelated haberikra.com.
  • no_csp manifest content_security_policy is null; MV3 default applies but innerHTML sink increases risk.
  • dom_xss_sink crx js/popup.js: popupContainer.innerHTML = html — DOM-XSS sink without sanitization.
  • maintenance_stale store Last updated June 2025 (15 months ago); 6-12mo band applies → +3.5 maintenance.

Permissions Breakdown

  • search medium Allows querying browser search; paired with newtab override suggests search monetization.
  • chrome_url_overrides.newtab medium Replaces every new tab page — high daily reach, monetization vector.
  • host_permissions: https://api.gameograf.com/* low Scoped to developer's own API domain; narrow host access.

Pillar Scores

Permissions4.00
Reputation5.50
Network2.00
Webstore7.50
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 13:01
Listing SHA 1e4bdb32ac4d…
Force block — not fired
Score recovered no
Elapsed