Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Kurumi Tokisaki Wallpapes New Tab by Gameograf

njmmkihfijbienkekhghajkmkpcemikk
Risk Score
5.72
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category NewTab
Installs 269
Rating 4.5
Last updated 2025-06-06 (15 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@gameograf.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Google's generic privacy policy used — does not scope data collection to this extension at all (Privacy +10.0).
  • NewTab override with install/uninstall URL hijack to gameograf.com — classic traffic-monetization shell pattern.
  • Uninstall URL hijack detected: redirects to gameograf.com on removal (+3.0 Webstore).
  • Install URL hijack detected: opens gameograf.com on install (+2.0 Webstore).
  • No CSP present (MV3 mitigates somewhat) plus innerHTML DOM-XSS sink in popup.js.

Evidence

  • newtab_override manifest chrome_url_overrides.newtab = index.html; monetization-shape new-tab override.
  • uninstall_url_hijack crx setUninstallURL → https://gameograf.com/?utm_source=uninstall; 3rd-party redirect confirmed.
  • install_url_hijack crx onInstalled opens https://gameograf.com/?utm_source=install; traffic capture on install.
  • generic_privacy_policy api Privacy policy URL is Google's own policy (myaccount.google.com); scope_extension=false, data_collection=true, third_party_sharing=true.
  • dom_xss_sink crx js/popup.js: innerHTML assigned from variable without sanitization; no CSP to mitigate.
  • no_developer_name store developer_name is empty string; reduces accountability.
  • verified_publisher_stale store verified_publisher=true but months_since_update=15; v3.5-E cap applies (-1.0 max discount).
  • external_host_mlionltd_github_io crx js_external_hosts includes mlionltd.github.io — unknown 3rd-party GitHub Pages domain.

Permissions Breakdown

  • search medium Allows reading/modifying search provider; combined with newtab override raises monetization concern.
  • host_permissions: https://api.gameograf.com/* low Scoped to developer's own API domain; low surface but enables data exfil to dev server.
  • chrome_url_overrides: newtab medium Replaces new-tab page; common monetization/traffic-capture vector.

Pillar Scores

Permissions4.00
Reputation4.00
Network2.50
Webstore8.00
Maintenance6.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 06:57
Listing SHA 81b835e52c95…
Force block — not fired
Score recovered no
Elapsed