Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Honda CBR1000RR Wallpapers

mggiclknhmmfhcebdeelhbhfggpbdjep
Risk Score
5.74
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category NewTab
Installs 247
Rating 5.0
Last updated 2025-05-29 (16 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@gameograf.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • NewTab override with uninstall URL hijack and install URL hijack — classic monetization shell pattern.
  • Privacy policy is Google's generic policy; not scoped to this extension, yet admits data collection and 3rd-party sharing → Privacy pillar 10.
  • No CSP (MV3 default stricter but csp_present==false) combined with innerHTML DOM-XSS sink in popup.js.
  • Stale 16 months with newtab override increases long-term exposure risk.
  • External JS host mlionltd.github.io (GitHub Pages, uncontrolled third party) present in js_external_hosts.

Evidence

  • uninstall_url_hijack manifest setUninstallURL → https://gameograf.com/?utm_source=uninstall... — traffic monetization indicator.
  • install_url_hijack manifest onInstalled opens https://gameograf.com/?utm_source=install... — monetization shell pattern.
  • newtab_override manifest chrome_url_overrides.newtab = index.html; full new-tab replacement.
  • generic_privacy_policy store Privacy URL is Google's own policy (myaccount.google.com/privacypolicy); scope_extension=false, data_collection=true, third_party_sharing=true.
  • dom_xss_sink crx popup.js uses innerHTML with variable input; no CSP to mitigate DOM-XSS.
  • external_uncontrolled_host crx mlionltd.github.io listed in js_external_hosts — GitHub Pages domain, not developer-controlled.
  • maintenance_stale store 16 months since last update; newtab override persists over this period.
  • no_csp manifest content_security_policy is null; csp_present=false; amplifies DOM-XSS risk.

Permissions Breakdown

  • search medium Allows overriding search provider; medium risk on its own.
  • host_permission: https://api.gameograf.com/* low Scoped to developer's own API domain; limited blast radius.
  • chrome_url_overrides.newtab medium Replaces new-tab page; monetization surface and user-experience takeover.

Pillar Scores

Permissions5.00
Reputation5.00
Network2.00
Webstore8.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 15:14
Listing SHA 2791dc9a0bc0…
Force block — not fired
Score recovered no
Elapsed