Barbarian Warrior Princess Live Wallpaper
bfjnepjapmanfhcgojjahllfcafafldn
Risk Score
3.34
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- NewTab override with search permission creates monetization surface on every new tab opened.
- Uninstall and install URL hijack both redirect to gameograf.com marketing URL.
- Two innerHTML DOM-XSS sinks in popup.js and calendar.js with no CSP to mitigate.
- No developer name listed; verified publisher but empty 'Offered by' field reduces accountability.
- Very low install count (10) limits blast radius but reduces trust signal from community usage.
Evidence
- newtab_override manifest chrome_url_overrides.newtab set to newtab.html; search permission also declared — monetization shape.
- uninstall_url_hijack crx setUninstallURL targets https://gameograf.com/?utm_source=extension&utm_medium=install
- install_url_hijack crx onInstalled opens https://gameograf.com/?utm_source=extension&utm_medium=install
- dom_xss_sinks crx innerHTML assigned from variable in js/popup.js and js/calendar.js; no CSP present to block exploitation.
- no_csp manifest content_security_policy is null; MV3 default applies but no explicit hardening.
- verified_publisher store verified_publisher == true; domain gameograf.com resolves and is not throwaway.
- privacy_policy api Policy fetched, scoped to extension, documents collection/retention/third-party sharing — adequate.
- empty_developer_name store developer_name is empty string despite verified publisher status; reduces accountability signal.
Permissions Breakdown
- search medium Allows querying search provider; relevant for NewTab override monetization shape.
- host_permissions: https://api.gameograf.com/* medium Scoped to developer domain; used for wallpaper/config API calls.
- chrome_url_overrides.newtab medium Replaces new-tab page; high-frequency touch-point enabling search monetization.
Pillar Scores
Permissions3.00
Reputation4.00
Network2.50
Webstore6.00
Maintenance1.50
Privacy0.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 09:08
Listing SHA
275805af3fd5…
Force block
— not fired
Score recovered
no
Elapsed
—