Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Yamato One Piece Live Wallpaper New Tab

mikbojmagjaoohiocajbdnjedobmdaan
Risk Score
3.49
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category NewTab
Installs 1,000
Rating 5.0
Last updated 2026-08-19 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@gameograf.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • NewTab override replaces every new tab page — persistent high-reach monetization surface with uninstall/install URL hijacks.
  • Uninstall and install URL hijacks fire tracking beacons to gameograf.com on every install/remove event.
  • No developer name listed, lowering accountability; extension is a fan-content shell around an anime theme.
  • innerHTML DOM-XSS sink in calendar.js with no CSP — low exploitability but present code quality gap.
  • No CSP on MV3 extension; csp_present==false adds minor network risk on an extension contacting 12 external hosts.

Evidence

  • newtab_override manifest chrome_url_overrides.newtab set to newtab.html — replaces every new tab for all users.
  • uninstall_url_hijack crx setUninstallURL targets https://gameograf.com/?p=6196?utm_source=extension&utm_medium=uninstall (+3.0 Webstore).
  • install_url_hijack crx onInstalled opens https://gameograf.com/?p=6196?utm_source=extension&utm_medium=install (+2.0 Webstore).
  • no_developer_name store developer_name is empty string — no 'Offered by' identity visible (+1.0 Reputation).
  • dom_sink_innerhtml crx innerHTML sink in js/calendar.js without CSP — DOM-XSS risk, no obfuscation detected.
  • no_csp manifest content_security_policy is null; csp_present==false on MV3 extension contacting 12 external JS hosts.
  • privacy_policy_adequate api Policy fetched, scoped to extension, discloses data collection, retention, and third-party sharing. Privacy pillar low.
  • fan_content_shell store Anime character wallpaper NewTab with no stated primary function beyond theming — fan-content shell pattern (+1.5 Webstore).

Permissions Breakdown

  • search medium Allows reading and potentially influencing search provider; notable for a NewTab extension.
  • alarms low Scheduling only; minimal risk.
  • storage low Local data persistence; standard.
  • chrome_url_overrides.newtab medium Replaces every new tab — high reach, monetization surface.
  • host_permissions: https://api.gameograf.com/* medium Scoped to developer's own API; acceptable but still an outbound channel.

Pillar Scores

Permissions3.00
Reputation6.00
Network2.00
Webstore7.50
Maintenance0.00
Privacy1.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 06:47
Listing SHA b99a2c5675e8…
Force block — not fired
Score recovered no
Elapsed