Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Neymar New Tab Wallpaper

pgoggeffkmknnmdjopemmfcdhfglhgha
Risk Score
5.54
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category NewTab
Installs 2,000
Rating 5.0
Last updated 2025-07-02 (14 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@gameograf.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • NewTab override with uninstall+install URL hijack to gameograf.com — clear monetization shell pattern.
  • Privacy policy is Google's own policy (scope_extension=false, data_collection=true, third_party_sharing=true) — not scoped to this extension.
  • No developer name listed; no 'Offered by' identity beyond email; verified_publisher mitigated but not enough.
  • External JS host mlionltd.github.io is a third-party GitHub Pages domain with no clear affiliation to developer.
  • NewTab + search override combo with 14-month-old build and no CSP elevates maintenance and governance risk.

Evidence

  • uninstall_url_hijack + install_url_hijack crx Both onInstalled and uninstall redirect to gameograf.com with UTM params — monetization shell pattern.
  • chrome_url_overrides.newtab manifest NewTab override captures every new tab; combined with search permission raises monetization risk.
  • privacy_policy_generic api Policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • external_js_host_third_party crx mlionltd.github.io listed in js_external_hosts — unaffiliated GitHub Pages domain.
  • no_developer_name store developer_name is empty string; no 'Offered by' identity disclosed in listing.
  • dom_sink_innerhtml_userctrl crx js/popup.js assigns user-controlled variable to innerHTML — DOM-XSS risk without CSP.
  • csp_absent_mv3 manifest content_security_policy is null; MV3 has strict default but no explicit CSP declared.
  • months_since_update_14 store Last updated July 2025 (~14 months); 6-12 month band (+3.5 maintenance).

Permissions Breakdown

  • search medium Allows overriding search provider — medium monetization risk.
  • host_permissions: https://api.gameograf.com/* low Scoped to developer's own API domain; limited blast radius.
  • chrome_url_overrides.newtab medium NewTab override with monetization shape; captures high-frequency user touchpoint.

Pillar Scores

Permissions4.00
Reputation5.00
Network2.00
Webstore7.50
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 04:55
Listing SHA 1075d348ef5c…
Force block — not fired
Score recovered no
Elapsed