Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Lilo & Stitch Wallpapers by Gameograf

nlnegpolflkiidndjnkcmdfobamfkmno
Risk Score
6.04
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category NewTab
Installs 144
Rating
Last updated 2025-05-30 (16 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@gameograf.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Google privacy policy used as extension policy — admits data collection & 3rd-party sharing with no extension-specific scoping.
  • New-tab override + search permission = search-monetization shell; uninstall/install URL hijack confirms traffic-monetization pattern.
  • No developer name listed; unverified publisher with throwaway-style extension title.
  • DOM-XSS sink (innerHTML from variable) in popup.js with no CSP to mitigate.
  • Extension contacts mlionltd.github.io (3rd-party GitHub Pages host) — unexplained external dependency.

Evidence

  • newtab_override_with_search_perm manifest chrome_url_overrides.newtab + 'search' permission = classic search-monetization NewTab pattern.
  • uninstall_and_install_url_hijack crx Both onInstalled and setUninstallURL redirect to gameograf.com with UTM params — dual traffic hijack.
  • privacy_policy_generic_google store Policy URL is myaccount.google.com/privacypolicy — Google's own policy, not scoped to this extension.
  • privacy_policy_classification_admits_collection api fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy pillar.
  • no_developer_name store developer_name is empty string; no verified publisher badge.
  • dom_xss_sink_no_csp crx innerHTML from variable in popup.js; csp_present=false on MV3 extension leaves no mitigation.
  • external_host_mlionltd_github_io crx js_external_hosts includes mlionltd.github.io — unrecognized 3rd-party GitHub Pages host.
  • stale_16mo_newtab store 16 months since update on a NewTab monetization extension; fits triple-stale fingerprint partially.

Permissions Breakdown

  • search medium Allows override of search provider; paired with newtab override is a monetization vector.
  • host_permissions: https://api.gameograf.com/* low Scoped to dev's own API domain; limited blast radius.
  • chrome_url_overrides.newtab medium Replaces new-tab page; high-impression surface for search monetization.

Pillar Scores

Permissions5.00
Reputation6.00
Network3.50
Webstore8.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 14:53
Listing SHA cb8e2fbacc0a…
Force block — not fired
Score recovered no
Elapsed