Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Metallica Live Wallpaper

nknfkoclcfkmbcikgeogopcmhpponbpo
Risk Score
5.66
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category NewTab
Installs 552
Rating 5.0
Last updated 2026-06-22 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer poyrazolcay62@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • NewTab override + uninstall/install URL hijack to yowgames.com — classic ad-monetization shell pattern.
  • Privacy policy is Google's own account policy (scope_extension=false, data_collection=true, 3rd-party sharing=true) — triggers +10.0 privacy score per v3.5 rule D.
  • Free-webmail developer (gmail) with no business website, no verified publisher badge — unaccountable operator.
  • Search permission paired with newtab override enables full search-provider monetization without user consent.
  • Install and uninstall URL hijacks redirect to yowgames.com, indicating third-party traffic monetization.

Evidence

  • newtab_override manifest chrome_url_overrides.newtab = index.html; replaces every new tab for all users.
  • uninstall_url_hijack crx setUninstallURL targets https://yowgames.com/uninstall — third-party traffic capture on removal.
  • install_url_hijack crx onInstalled opens https://yowgames.com/metallica-live-wallpaper — third-party install redirect.
  • privacy_policy_generic store PP is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true — rule D applies.
  • free_webmail_dev store Developer email poyrazolcay62@gmail.com with no associated business domain or verified publisher.
  • newtab_monetization_shape crx js_external_hosts includes yowgames.com, major platforms (Netflix, YouTube, Instagram, X) as link targets.
  • search_permission_newtab manifest search permission + newtab override enables full search monetization without high-permission declaration.
  • no_csp manifest content_security_policy is null; MV3 defaults apply but no explicit CSP declared.

Permissions Breakdown

  • search medium Allows overriding search provider; medium-risk alone but paired with newtab override raises concern.
  • chrome_url_overrides.newtab high Replaces new tab page; primary mechanism for ad-monetization shells and traffic hijacking.

Pillar Scores

Permissions4.00
Reputation7.50
Network0.00
Webstore10.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 13:19
Listing SHA 1d1592593c10…
Force block — not fired
Score recovered no
Elapsed