Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

BLACKPINK Wallpapers New Tab Lisa Rose Jennie Jisoo

nmknbcamoginleehgkmlilgnkhkphgdh
Risk Score
5.73
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category NewTab
Installs 2,000
Rating 4.6
Last updated 2025-05-21 (16 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@gameograf.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Google's own privacy policy used — not scoped to this extension, admits data collection and 3rd-party sharing (+10 privacy).
  • Uninstall and install URL hijacks redirect users to gameograf.com tracking links (+3+2 webstore).
  • bit.ly affiliate/cloaking link in JS hosts — redirects destination opaque (+1.5 webstore).
  • NewTab override controls every new tab session; combined with 'search' permission enables search monetization.
  • months_since_update=16 (12-24mo band) and no CSP — DOM-XSS sink in popup.js unmitigated.

Evidence

  • uninstall_url_hijack crx chrome.runtime.setUninstallURL to gameograf.com with UTM tracking params — monetization redirect.
  • install_url_hijack crx onInstalled opens gameograf.com with UTM tracking — install hijack confirmed.
  • privacy_policy_google_generic store Privacy URL is myaccount.google.com/privacypolicy — Google's policy, not scoped to this extension.
  • privacy_policy_classification api scope_extension=false, data_collection=true, third_party_sharing=true — D-clause: +10.0 privacy.
  • affiliate_hit_bitly crx bit.ly in js_external_hosts — generic short-link redirector flagged as affiliate/cloaking.
  • newtab_override_search_perm manifest chrome_url_overrides.newtab + search permission — classic search-monetization NewTab shell.
  • dom_sink_innerhtml crx popup.js assigns innerHTML from variable with no CSP — DOM-XSS risk unmitigated.
  • no_developer_name store developer_name is empty string — no 'Offered by' identity presented to users.

Permissions Breakdown

  • search medium Allows search-provider interaction; paired with newtab override amplifies monetization risk.
  • host_permissions: https://api.gameograf.com/* low Scoped to developer's own API domain; low breadth but enables data exfil to dev server.
  • chrome_url_overrides.newtab medium Replaces every new tab with extension page; high user-reach monetization surface.

Pillar Scores

Permissions3.50
Reputation5.50
Network2.00
Webstore8.50
Maintenance6.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 12:46
Listing SHA 2d9f608bc0bc…
Force block — not fired
Score recovered no
Elapsed