Satoru Gojo: Unleash the Power of Jujutsu! Gameograf
ohaanogfieieninnekoplcannhhagbih
Risk Score
5.57
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's own generic policy — scope_extension=false, admits data collection and 3rd-party sharing; scores 10.0.
- No last_updated date available — maintenance scored at maximum (10.0); extension age unknowable.
- NewTab override with uninstall/install URL hijack to gameograf.com is a monetization-shell pattern.
- mlionltd.github.io in js_external_hosts is an unverified third-party GitHub Pages endpoint.
- innerHTML assignment from variable in popup.js (DOM-XSS sink) with no CSP present.
Evidence
- newtab_override manifest chrome_url_overrides.newtab = index.html; every new tab is developer-controlled.
- uninstall_url_hijack crx setUninstallURL → gameograf.com with UTM params; classic monetization-shell signal.
- install_url_hijack crx onInstalled opens gameograf.com with UTM params; install redirect.
- generic_privacy_policy store Privacy URL is myaccount.google.com/privacypolicy — Google's policy, not developer's; scope_extension=false.
- no_last_updated store last_updated field is empty string; maintenance pillar cannot be scored below maximum.
- external_host_github_pages crx js_external_hosts includes mlionltd.github.io — unverified third-party endpoint.
- dom_xss_sink_no_csp crx innerHTML set from variable in popup.js; csp_present=false amplifies risk per FIX B.
- no_developer_name store developer_name is empty string; identity accountability reduced.
Permissions Breakdown
- search medium Allows search-provider interaction; paired with newtab override amplifies monetization surface.
- host_permissions: https://api.gameograf.com/* low Scoped to developer's own API domain; limited blast radius.
- chrome_url_overrides.newtab medium Replaces every new tab with developer-controlled page; persistent monetization surface.
Pillar Scores
Permissions3.50
Reputation2.50
Network2.00
Webstore6.00
Maintenance10.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 11:51
Listing SHA
a67f2397486c…
Force block
— not fired
Score recovered
no
Elapsed
—