Anime Girl Next to Audi Live Wallpaper New Tab Theme
adcfdligdikcmidcfdhagnaofjdhlkom
Risk Score
3.59
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- NewTab override + search permission = full search monetization shell with uninstall/install URL hijacks to gameograf.com.
- Both install and uninstall URL hijack to third-party domain detected — classic traffic-monetization pattern.
- DOM-XSS sinks (innerHTML from variables) in popup.js and calendar.js with no CSP — elevated XSS risk.
- No developer name listed; verified publisher alone insufficient for accountability.
- 66 installs with no ratings — minimal community signal, tail-attack-surface concern.
Evidence
- newtab_override manifest chrome_url_overrides.newtab set to newtab.html — every new tab controlled by extension.
- install_uninstall_hijack manifest Both install and uninstall URLs redirect to gameograf.com with UTM params — monetization pattern.
- dom_xss_no_csp crx innerHTML sinks in popup.js and calendar.js; csp_present==false; MV3 mitigates but risk remains.
- no_developer_name store developer_name is empty string; verified_publisher is true but name absent reduces accountability.
- verified_publisher store verified_publisher=true applied -3.0 reputation discount (floor 2.0 respected).
- privacy_policy_adequate api Policy fetched; scope_extension, data_collection, retention, third_party_sharing all true. +1.0 for retention.
- low_installs store Only 66 installs, 0 ratings — no popularity signals; tail extension.
- jquery_3.7.1_no_cve crx jquery 3.7.1 detected; no CVEs in cve_findings_raw — no CVE pillar penalty.
Permissions Breakdown
- search medium Allows reading search terms; paired with NewTab override gives full search monetization surface.
- host_permissions: https://api.gameograf.com/* low Scoped to developer's own API domain only.
- chrome_url_overrides.newtab medium Replaces every new tab — high-reach, monetization-shell pattern for NewTab category.
Pillar Scores
Permissions3.00
Reputation4.50
Network0.00
Webstore7.00
Maintenance1.50
Privacy1.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 10:36
Listing SHA
e449939ed016…
Force block
— not fired
Score recovered
no
Elapsed
—