Toyota Supra Orange Live Wallpaper
bbdjfoaempahipccjhfngldjghjekkkf
Risk Score
5.62
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- NewTab override replaces every new tab with monetization shell; install+uninstall URL hijacks to gameograf.com.
- Privacy policy is Google's generic policy — does not scope to this extension; admits data collection & 3rd-party sharing.
- Two innerHTML sinks (calendar.js, popup.js) with no CSP present — DOM-XSS risk elevated.
- Uninstall and install URL hijacks route users to developer's marketing funnel.
- Extension is 13 months stale (6–24mo band) with no verified publisher accountability.
Evidence
- newtab_override manifest chrome_url_overrides.newtab set to newtab.html — replaces every new tab.
- install_uninstall_hijack crx install_url_hijack and uninstall_url_hijack both true, redirecting to gameograf.com marketing URLs.
- generic_privacy_policy store Privacy URL is Google's global policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- no_csp manifest content_security_policy is null; csp_present=false — no script-src protection.
- dom_xss_sinks crx Two dom_sink_innerhtml_userctrl findings in calendar.js and popup.js; no CSP amplifies risk.
- stale_extension store Last updated August 2025 but months_since_update=13, placing it in the 12–24mo maintenance band.
- no_verified_publisher store verified_publisher=false, is_featured_by_google=false; no accountability signals.
- newtab_monetization_pattern crx NewTab + search override + install/uninstall hijack = classic traffic-monetization cluster.
Permissions Breakdown
- search medium Allows reading/modifying search provider — medium risk on its own.
- host_permissions: https://api.gameograf.com/* low Scoped to developer's own API domain; narrow but enables data exfil to dev.
- chrome_url_overrides.newtab medium Replaces every new tab — high reach, monetization surface, per v2(a).
Pillar Scores
Permissions4.00
Reputation5.00
Network2.00
Webstore8.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 10:50
Listing SHA
01dc0bdf1eee…
Force block
— not fired
Score recovered
no
Elapsed
—