Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

McLaren W1 Wallpapers New Tab

ljekjledibfmiklmendbpmophiphhkmm
Risk Score
3.42
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category NewTab
Installs 139
Rating 5.0
Last updated 2025-05-29 (16 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@gameograf.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • NewTab override replaces every new tab with developer-controlled content; persistent high-reach surface.
  • Uninstall and install URL hijacks redirect users to developer tracking URLs on lifecycle events.
  • innerHTML sink in popup.js is a DOM-XSS vector if content from api.gameograf.com is unsanitized.
  • Extension is 16 months stale with no CSP, leaving DOM-XSS sink unmitigated.
  • mlionltd.github.io as external JS host is a third-party GitHub Pages domain outside developer control.

Evidence

  • newtab_override manifest chrome_url_overrides.newtab replaces every new tab page with index.html.
  • uninstall_url_hijack crx setUninstallURL targets https://gameograf.com with UTM tracking params.
  • install_url_hijack crx onInstalled opens https://gameograf.com with UTM tracking params.
  • dom_xss_sink crx js/popup.js assigns innerHTML from variable; no CSP to mitigate XSS.
  • external_js_host_third_party crx mlionltd.github.io is an external JS host not under developer domain control.
  • no_csp manifest content_security_policy is null; MV3 default applies but DOM sink is unmitigated.
  • stale_extension store 16 months since last update; triple-stale fingerprint (>12mo, MV3, no CVEs).
  • verified_publisher store Developer is verified publisher; resolves domain gameograf.com; reduces reputation risk.

Permissions Breakdown

  • search medium Allows querying browser search API; medium risk for a NewTab override extension.
  • host_permission: https://api.gameograf.com/* low Scoped to developer's own API domain only.
  • chrome_url_overrides.newtab medium Replaces every new tab page; persistent high-reach surface for monetization or phishing.

Pillar Scores

Permissions3.00
Reputation3.50
Network2.50
Webstore6.50
Maintenance6.00
Privacy1.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 14:48
Listing SHA 18d59e8e0d53…
Force block — not fired
Score recovered no
Elapsed