Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Ducati 1199 Panigale Live Wallpaper

iabmfgocbkjimgoemlobdmljomdilini
Risk Score
3.56
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category NewTab
Installs 562
Rating 5.0
Last updated 2026-08-18
Manifest version MV3
CSP present ❌ no
Developer support@gameograf.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • NewTab override replaces every new tab page, intercepting navigation for all users.
  • Uninstall URL hijack sends users to developer marketing page on removal.
  • Install URL hijack redirects users to third-party page on install.
  • DOM-XSS sink (innerHTML) in calendar.js with no CSP to mitigate exploitation.
  • No developer name listed; publisher accountability is weak despite verified_publisher flag.

Evidence

  • newtab_override manifest chrome_url_overrides.newtab set to newtab.html — replaces every new-tab page.
  • uninstall_url_hijack crx setUninstallURL targets https://gameograf.com/?p=33124?utm_source=extension&utm_medium=uninstall
  • install_url_hijack crx onInstalled opens https://gameograf.com/?p=33124?utm_source=extension&utm_medium=install
  • dom_xss_sink crx innerHTML assigned from variable in js/calendar.js; no CSP to block exploitation.
  • no_csp manifest content_security_policy is null; MV3 default applies but no explicit hardening.
  • verified_publisher store verified_publisher=true with resolving domain gameograf.com; partial trust signal.
  • no_developer_name store developer_name is empty string; reduces accountability.
  • privacy_policy_adequate api Policy fetched; scope_extension, data_collection, retention, third_party_sharing all true.

Permissions Breakdown

  • search medium Can read and manipulate search queries; elevated for a wallpaper/NewTab extension.
  • alarms low Scheduling only; minimal risk.
  • storage low Local settings persistence; low risk.
  • chrome_url_overrides.newtab medium Replaces new-tab page; monetization surface, intercepts user navigation intent.
  • host_permissions: https://api.gameograf.com/* low Scoped to developer's own API domain; single-origin, low blast radius.

Pillar Scores

Permissions4.30
Reputation4.00
Network2.00
Webstore7.50
Maintenance0.00
Privacy0.00
Code Quality0.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 12:18
Listing SHA 0ecd4e910868…
Force block — not fired
Score recovered no
Elapsed