Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Little Twin Stars Wallpaper

jocdlimckippcledbhdpchljgafhacbe
Risk Score
6.07
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category NewTab
Installs 751
Rating 5.0
Last updated 2025-05-14 (15 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@gameograf.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • NewTab override replaces every new tab; combined with search permission enables full search monetization.
  • Privacy policy is Google's generic policy — does not scope data collection to this extension at all.
  • Uninstall and install URL hijack to gameograf.com tracking parameters; monetization shell pattern.
  • External JS host bit.ly flagged as affiliate/cloaking redirector — actual destination opaque.
  • months_since_update=15 with newtab override and no CSP elevates staleness risk.

Evidence

  • newtab_override manifest chrome_url_overrides.newtab = index.html; replaces every new tab for all 751 users.
  • uninstall_and_install_url_hijack crx Both onInstalled and onUninstall redirect to gameograf.com with UTM tracking params.
  • affiliate_hit_bitly crx bit.ly listed in js_external_hosts; threat_intel flags as affiliate/cloaking short-link.
  • generic_google_privacy_policy store Privacy URL is myaccount.google.com/privacypolicy — not scoped to this extension.
  • no_csp manifest content_security_policy is null; no CSP declared on MV3 extension.
  • dom_xss_sink crx innerHTML assigned from variable in js/popup.js with no CSP mitigation.
  • stale_newtab_no_csp store 15 months since update, newtab override, no CSP — elevated staleness+capability risk.
  • verified_publisher_cap_applied store Verified publisher but months_since_update=15 >12 — v3.5(0c) caps discount to -1.0.

Permissions Breakdown

  • search medium Allows altering search provider; newtab override compounds this risk.
  • chrome_url_overrides.newtab high Replaces every new tab page; high reach over user browsing sessions.
  • host_permissions: https://api.gameograf.com/* low Scoped to dev-controlled domain; limited blast radius.

Pillar Scores

Permissions5.50
Reputation5.00
Network2.00
Webstore9.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 12:05
Listing SHA 4f2d3961b850…
Force block — not fired
Score recovered no
Elapsed