Titans City Destruction Live Wallpaper
ammndifopdgpjcpmpbdenfcafipnejlj
Risk Score
3.39
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- NewTab override replaces every new tab; combined with uninstall/install URL hijack signals monetization intent.
- Both install and uninstall URL hijack active — classic traffic-monetization shell pattern.
- Two innerHTML DOM-XSS sinks (popup.js, calendar.js) with no CSP; elevated injection risk.
- No developer name listed; verified publisher but empty 'Offered by' field reduces accountability.
- Extension contacts 12 external JS hosts including Google services and OpenAI beyond stated function.
Evidence
- newtab_override manifest chrome_url_overrides.newtab = newtab.html; replaces all new-tab pages.
- uninstall_url_hijack crx setUninstallURL -> https://gameograf.com/?utm_source=extension&utm_medium=install
- install_url_hijack crx onInstalled opens https://gameograf.com/?utm_source=extension&utm_medium=install
- dom_xss_sinks crx innerHTML from variable in popup.js and calendar.js; csp_present=false amplifies risk.
- no_csp manifest content_security_policy is null; MV3 default CSP applies but no explicit extension CSP declared.
- external_js_hosts crx 12 external hosts including chat.openai.com, multiple Google services beyond stated wallpaper purpose.
- verified_publisher store Verified publisher badge present for gameograf.com; domain resolves; not throwaway.
- privacy_policy api Policy fetched; scope_extension=true, data_collection=true, retention=true, third_party_sharing=true.
Permissions Breakdown
- search medium Allows reading/modifying search queries; medium risk for a NewTab extension.
- host_permissions: https://api.gameograf.com/* low Scoped to developer's own API domain; limited blast radius.
- chrome_url_overrides.newtab medium Replaces new-tab page; monetization and tracking vector for all new tabs.
Pillar Scores
Permissions3.50
Reputation3.50
Network2.00
Webstore7.00
Maintenance1.50
Privacy0.00
Code Quality2.00
CVE Exposure0.00
Operator Siblings (15)
Other extensions sharing this developer's compound fingerprint:
- fdjpcjggpgdmdikmhoagohakklihimbo
- ojhigfemmjpjnmhidflhdlcahgdiiija
- ieocbmlfbinpcffofcjmpbjokkfghodc
- faaegcmakhlmoheamicddkfcmmjoljnd
- amfeinhgbpnnjihjiomibeodnainnjkd
- ceoamfmlgefiljnligpdkdindckojbim
- hlacaekdajdgiiofjplpofbgebgjbnco
- lcoeefcacppckhidgmkdlnbeajkmeick
- kngkldhmcncemclgjgbbogplfeoppkll
- gfcbimjpmoeofbmnjedjfkemdinagkmp
- kmjgnidfglamdnllpoidpfikcodjapih
- heakmhbelclpalglpiceoocofnkcjefb
- gbeldgdcloiceglhpdnkhbafeoddjehm
- epjpkhahnajkdjjfkeadcgfmfjfgdohf
- fjmlhfejlohohljeioedcliggbfkihdf
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 10:33
Listing SHA
25f79336942a…
Force block
— not fired
Score recovered
no
Elapsed
—