Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Lisa Newest Photos Wallpaper by Gameograf

pikefoaagadfjcgbhgdhdboefoohdpbe
Risk Score
5.49
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category NewTab
Installs 515
Rating 5.0
Last updated 2025-09-08 (12 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@gameograf.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy URL returns HTTP error — effectively no policy; unknown data collection practices.
  • NewTab override + search permission = persistent monetization/redirect surface on every browser tab.
  • Uninstall and install URL hijack to gameograf.com tracking links; classic monetization shell pattern.
  • Operator cluster: 6 extensions share same dev email, 9 share install URL — high-volume shell factory.
  • innerHTML user-controlled sink in popup.js with no CSP — DOM-XSS risk if API response is attacker-controlled.

Evidence

  • privacy_policy_fetch_error api Privacy policy URL returned HTTPError; fetched=false → +10.0 Privacy pillar.
  • newtab_override_and_search_permission manifest chrome_url_overrides.newtab + search permission: monetization NewTab shell pattern.
  • install_uninstall_url_hijack crx Both onInstalled and uninstall redirect to gameograf.com with UTM tracking params.
  • operator_cluster_shell_factory api dev_email shared by 6 extensions; install_url shared by 9; sibling_count=1 compound match.
  • dom_xss_sink_no_csp crx innerHTML from variable in popup.js; csp_present=false; MV3 mitigates somewhat.
  • external_host_mlionltd_github_io crx JS contacts mlionltd.github.io — third-party GitHub Pages host not explained by stated function.
  • developer_name_missing store developer_name is empty string; no 'Offered by' identity beyond email domain.
  • verified_publisher store verified_publisher=true; partial -1.0 discount applied (invariant 0c: monetization hits absent but shell pattern present).

Permissions Breakdown

  • search medium Allows overriding search provider; core monetization vector for NewTab shells.
  • host_permissions: https://api.gameograf.com/* low Scoped to own API domain; limited blast radius but enables telemetry/data exfil.
  • chrome_url_overrides: newtab medium Replaces every new tab — persistent monetization surface on every new tab open.

Pillar Scores

Permissions4.00
Reputation4.00
Network2.00
Webstore8.50
Maintenance3.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-15 13:07
Listing SHA 7c5327163732…
Force block — not fired
Score recovered no
Elapsed