Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

DanDaDan Live Wallpaper

iolckjdgbdlbacipebcmbjelkjhdlmfl
Risk Score
6.07
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category NewTab
Installs 68
Rating
Last updated 2025-05-14 (16 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@haberikra.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy — not scoped to this extension; data collection and 3rd-party sharing admitted without extension-level disclosure.
  • NewTab override + 'search' permission = classic search-monetization shell pattern; uninstall and install URL hijacks confirmed.
  • No CSP (csp_present=false) with innerHTML DOM-XSS sink in popup.js raises injection risk.
  • Verified publisher discount capped at -1.0 per invariant 0c: months_since_update=16 >12 and no CSP present.
  • Developer name blank; extension has 68 installs with NewTab takeover and dual install/uninstall URL hijacks.

Evidence

  • uninstall_url_hijack + install_url_hijack manifest Both onInstalled and onUninstall redirect to haberikra.com with UTM tracking — monetization shell fingerprint.
  • chrome_url_overrides.newtab manifest Replaces every new tab page with operator-controlled newtab.html.
  • privacy_policy_generic store Policy URL is Google's own account privacy page — scope_extension=false, data_collection=true, third_party_sharing=true.
  • no_csp manifest content_security_policy is null; MV3 default applies but no explicit hardening, compounding innerHTML XSS risk.
  • dom_sink_innerhtml_userctrl crx js/popup.js assigns innerHTML from variable — DOM-XSS sink with no CSP mitigation.
  • verified_publisher_capped store Verified publisher discount capped to -1.0: months_since_update=16 triggers invariant 0c stale>18 is not met but csp_present=false is borderline.
  • search_permission + newtab manifest 'search' permission combined with newtab override is a known search-monetization pattern.
  • developer_name_blank store No 'Offered by' developer name surfaced in listing; reduces accountability.

Permissions Breakdown

  • search medium Allows reading and modifying search queries; combined with newtab override raises monetization concern.
  • host_permissions: https://api.gameograf.com/* medium Scoped host access to operator API; data exfil possible via this endpoint.
  • chrome_url_overrides.newtab medium Replaces every new tab — prime monetization/search-hijack surface.

Pillar Scores

Permissions4.00
Reputation5.50
Network2.00
Webstore8.50
Maintenance6.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 14:09
Listing SHA 877447562a33…
Force block — not fired
Score recovered no
Elapsed