Cinnamoroll Live Wallpapers
bfecpeifiedmjpkdbhohaajlgjjgohhi
Risk Score
6.18
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- NewTab override with uninstall/install URL hijack to haberikra.com — classic monetization shell.
- Privacy policy is Google's own policy (not scoped to this extension); admits data collection & 3rd-party sharing → Privacy score 10.
- No developer name listed; verified_publisher present but months_since_update=15 and monetization signals cap the discount.
- install+uninstall URL hijacks both fire callbacks to haberikra.com with UTM tracking params.
- DOM-XSS sink (innerHTML from variable) in popup.js with no CSP present.
Evidence
- newtab_override manifest chrome_url_overrides.newtab = newtab.html — full new-tab replacement.
- uninstall_url_hijack crx setUninstallURL → https://haberikra.com/?utm_source=gameograf&utm_medium=link&utm_campaign=bg&utm_content=uninstall
- install_url_hijack crx onInstalled opens https://haberikra.com/?utm_source=install&utm_medium=link&utm_campaign=bg&utm_content=install
- generic_privacy_policy store Privacy URL is myaccount.google.com/privacypolicy — Google's policy, not scoped to this extension.
- no_developer_name store developer_name is empty string; reduces accountability.
- dom_xss_sink crx js/popup.js: innerHTML assigned from variable with no CSP — DOM-XSS risk.
- verified_publisher_monetization_cap store Verified publisher discount capped at -1.0 due to monetization URL pattern (v3.5 invariant 0c/E).
- stale_15mo store months_since_update=15 → Maintenance +6.0; also caps verified-publisher discount.
Permissions Breakdown
- search medium Allows querying/overriding search; enables monetization via search hijack.
- host_permission: https://api.gameograf.com/* medium Scoped host access to external API used for wallpaper/content delivery.
- chrome_url_overrides.newtab medium Replaces new-tab page — prime monetization surface, intercepts all new-tab navigations.
Pillar Scores
Permissions5.00
Reputation5.50
Network2.50
Webstore9.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 09:08
Listing SHA
c2ee5de41e62…
Force block
— not fired
Score recovered
no
Elapsed
—