Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Sonic the Hedgehog

jligamdjilhpkiphokblbiioimjgiccn
Risk Score
5.74
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category NewTab
Installs 346
Rating 5.0
Last updated 2025-06-10 (15 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@gameograf.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is hosted on unrelated domain (haberikra.com), admits data collection + 3rd-party sharing without extension-specific scope — scores max privacy risk.
  • NewTab override combined with search permission is a classic monetization shell; uninstall and install URL hijacks confirm traffic-monetization intent.
  • Both install and uninstall URL hijacks open gameograf.com with UTM tracking params — aggressive user-funnel control.
  • No developer name listed; privacy policy domain differs from developer domain, reducing accountability.
  • stale at 15 months with newtab override and no CSP; innerHTML DOM-XSS sink in popup.js with no content-security-policy mitigation.

Evidence

  • newtab_override manifest chrome_url_overrides.newtab = newtab.html — replaces every new tab with extension-controlled page.
  • uninstall_url_hijack crx setUninstallURL targets gameograf.com with UTM campaign params — user funnel tracking on uninstall.
  • install_url_hijack crx onInstalled opens gameograf.com with UTM install params — install-time redirect.
  • privacy_policy_mismatch store Policy URL is haberikra.com/privacy-policy/ — different domain from developer domain gameograf.com; scope_extension=false, data_collection+3rd_party_sharing=true.
  • dom_xss_sink crx popup.js assigns innerHTML from variable without sanitization; no CSP to mitigate.
  • no_developer_name store developer_name is empty string — reduces accountability.
  • stale_newtab store 15 months since last update; NewTab extension with search override and no CSP.
  • verified_publisher store Extension has verified_publisher=true; partially mitigates reputation but does not explain policy domain mismatch.

Permissions Breakdown

  • search medium Allows override of search provider; paired with newtab override raises monetization risk.
  • host_permissions: https://api.gameograf.com/* low Scoped to developer's own API domain; limited blast radius.
  • chrome_url_overrides.newtab medium Replaces new-tab page — primary monetization vector for this category.

Pillar Scores

Permissions4.00
Reputation5.00
Network2.00
Webstore8.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-16 06:28
Listing SHA a9e8ea5175b6…
Force block — not fired
Score recovered no
Elapsed