Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Haunting Grim Reaper Live Wallpaper

jnljdbjlpfpbnbddpcjceeoejgnnagkm
Risk Score
6.15
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category NewTab
Installs 90
Rating 5.0
Last updated 2025-06-28 (15 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@haberikra.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy URL returns HTTP error — policy effectively absent; privacy pillar maxed at 10.
  • New-tab override with uninstall URL hijack and install URL hijack: classic monetization shell pattern.
  • No developer name listed; MV3 with no CSP raises DOM-XSS risk from innerHTML sink in popup.js.
  • Stale 15 months with newtab override and unverifiable privacy policy — elevated long-term risk.
  • Verified publisher discount capped at -1.0 (months_since_update > 18 threshold not met but policy unfetchable).

Evidence

  • uninstall_url_hijack manifest setUninstallURL to gameograf.com with UTM params — traffic monetization on removal.
  • install_url_hijack manifest onInstalled opens gameograf.com with UTM params — monetization on install.
  • newtab_override manifest chrome_url_overrides.newtab set to newtab.html — replaces every new tab.
  • privacy_policy_fetch_error api privacy_policy_classification.fetched==false (HTTPError) — policy inaccessible, scored +10.
  • dom_sink_innerhtml_userctrl crx js/popup.js assigns innerHTML from variable without sanitization — DOM-XSS risk.
  • no_developer_name store developer_name is empty string; identity unverifiable beyond email domain.
  • no_csp manifest content_security_policy is null; MV3 default applies but no explicit hardening.
  • maintenance_stale store 15 months since last update; 12-24mo band scores +6.0.

Permissions Breakdown

  • search medium Allows querying the browser search engine; combined with newtab override raises monetization concern.
  • chrome_url_overrides.newtab high Replaces new-tab page; primary vector for search monetization and user tracking.
  • host_permissions: https://api.gameograf.com/* medium Grants fetch access to developer's own API; data sent/received is unaudited.

Pillar Scores

Permissions5.00
Reputation5.50
Network4.00
Webstore9.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-15 13:09
Listing SHA fa8323a1c69c…
Force block — not fired
Score recovered no
Elapsed