Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Lamine Yamal Wallpapers Gameograf

pognhgjjeijdaemaidolkajdckdoofih
Risk Score
5.53
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category NewTab
Installs 3,000
Rating 4.8
Last updated 2025-05-28 (16 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@gameograf.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy (fetch failed, not extension-scoped); no data handling disclosure.
  • NewTab override with uninstall/install URL hijack to gameograf.com — classic monetization shell pattern.
  • External JS host mlionltd.github.io is unrecognized third-party GitHub Pages domain outside dev control.
  • No developer name listed; verified publisher but privacy policy is a third-party URL that couldn't be fetched.
  • Maintenance at 16 months stale; verified-publisher discount capped at -1.0 per invariant 0c (stale >18mo nearly reached, monetization context).

Evidence

  • newtab_override manifest chrome_url_overrides.newtab = index.html; search permission declared — NewTab monetization pattern.
  • uninstall_url_hijack crx setUninstallURL targets https://gameograf.com/?utm_source=uninstall — third-party UTM tracking.
  • install_url_hijack crx onInstalled opens https://gameograf.com/?utm_source=install — UTM monetization on install.
  • privacy_policy_fetch_failed api Privacy policy URL is Google's generic policy; fetch returned SSLError — not extension-scoped.
  • external_host_unrecognized crx js_external_hosts includes mlionltd.github.io — uncontrolled third-party GitHub Pages domain.
  • no_developer_name store developer_name is empty string; verified publisher but no display name raises accountability gap.
  • verified_publisher store verified_publisher=true provides some accountability; domain gameograf.com resolves, age 2050 days.
  • csp_absent_mv3 manifest content_security_policy is null; MV3 has strict default but no explicit CSP declared.

Permissions Breakdown

  • search medium Allows search provider manipulation; paired with newtab override amplifies monetization risk.
  • host_permission: https://api.gameograf.com/* low Scoped to dev-owned domain only; limited blast radius.
  • chrome_url_overrides.newtab medium Replaces new-tab page; classic monetization surface for ad injection and search hijacking.

Pillar Scores

Permissions4.00
Reputation4.50
Network2.50
Webstore7.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-16 00:29
Listing SHA ad745ab61511…
Force block — not fired
Score recovered no
Elapsed