Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Super Saiyan Goku Live Wallpaper

khldlkommddmelemmjbijjmjmkoagadi
Risk Score
6.12
Risk Level: High
Recommendation: 🚫 BLOCK
Category NewTab
Installs 704
Rating
Last updated 2026-05-03 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer halilseker3455@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall AND install URL hijack both redirect to gameograf.com ad-campaign URL — classic monetization shell.
  • Privacy policy is Google's own generic policy (scope_extension=false, data_collection=true, third_party_sharing=true) — counts as worse than no policy (+10).
  • NewTab override hijacks every new-tab page; combined with 'search' permission forms search-monetization pattern.
  • Free-webmail dev (gmail), no developer name, verified_publisher badge but no business domain — reputation floor.
  • JS external hosts include instagram.com, netflix.com, youtube.com, x.com alongside gameograf.com — broad ad-shell fingerprint.

Evidence

  • uninstall_url_hijack manifest chrome.runtime.setUninstallURL → gameograf.com with utm_source=ovkas; textbook ad-monetization uninstall redirect.
  • install_url_hijack manifest onInstalled opens gameograf.com with utm_source=ovkas; same campaign tag as uninstall URL.
  • newtab_override manifest chrome_url_overrides.newtab = index.html; every new tab served by extension for ad/search monetization.
  • generic_privacy_policy store Policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • free_webmail_no_dev_name store developer_email=halilseker3455@gmail.com; developer_name empty; no business domain — reputation floor triggered.
  • broad_js_external_hosts crx Extension contacts gameograf.com, instagram.com, netflix.com, youtube.com, x.com — ad-shell host fingerprint.
  • verified_publisher_claimed store verified_publisher=true but email is free webmail, no business domain, generic Google policy — badge integrity low.
  • csp_absent_mv3 manifest content_security_policy is null/false; MV3 default applies but no explicit hardening declared.

Permissions Breakdown

  • search medium Grants ability to query/observe search; paired with newtab override amplifies search-monetization risk.
  • chrome_url_overrides.newtab high Replaces every new-tab page with extension HTML; primary monetization vector for wallpaper shells.

Pillar Scores

Permissions4.00
Reputation7.50
Network2.00
Webstore10.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 12:02
Listing SHA f1caac2dfbcf…
Force block — not fired
Score recovered no
Elapsed