Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Furry Lofi Study Break Live Wallpaper

jgpbfkndicgcihpdaabjhofbapemadai
Risk Score
6.07
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category NewTab
Installs 535
Rating 4.9
Last updated 2025-08-26 (13 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@gameograf.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Google's privacy policy used as extension policy — admits data collection and 3rd-party sharing without scoping to this extension.
  • NewTab override + search permission creates search-interception / monetization surface on every new tab.
  • Install and uninstall URL hijack to gameograf.com with UTM tracking — confirmed monetization shell behavior.
  • No developer name listed; policy URL is generic Google policy not authored by this developer.
  • Two DOM-XSS innerHTML sinks with no CSP, increasing exploitability if extension data sources are compromised.

Evidence

  • privacy_policy_generic store Policy URL is Google's own account policy (myaccount.google.com); scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 Privacy (v3.5-D).
  • newtab_override manifest chrome_url_overrides.newtab set to newtab.html — NewTab monetization shape, +2.0 Webstore.
  • install_uninstall_hijack crx uninstall_url_hijack=true and install_url_hijack=true both pointing to gameograf.com with UTM params. +3.0+2.0 Webstore.
  • no_developer_name store developer_name is empty string; +1.0 Reputation for missing 'Offered by'.
  • dom_xss_sinks_no_csp crx Two innerHTML-userctrl sinks in calendar.js and popup.js; csp_present=false → +2.0 Code Quality (FIX B).
  • stale_12_to_24mo store months_since_update=13 → Maintenance +6.0 (6-12mo band edge; actually 13mo falls in 12-24mo band → +6.0).
  • no_csp_mv3 manifest content_security_policy is null; MV3 has strict default but no explicit CSP raises innerHTML-sink exploitability.
  • js_external_hosts_12_domains crx 12 external JS hosts spanning Google services + gameograf.com; >3 distinct registrable domains → +1.5 Network.

Permissions Breakdown

  • search medium Allows querying the browser's search API; combined with NewTab override elevates search interception risk.
  • chrome_url_overrides.newtab high Replaces every new tab — primary monetization vector for wallpaper shells.
  • host_permissions: https://api.gameograf.com/* low Scoped to dev-controlled domain only; acceptable for extension API calls.

Pillar Scores

Permissions5.00
Reputation6.50
Network2.00
Webstore7.50
Maintenance6.00
Privacy10.00
Code Quality4.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-16 07:04
Listing SHA 0fd7d9026cc9…
Force block — not fired
Score recovered no
Elapsed