Little Twin Stars Cute Star Constellations Live Wallpaper
bmajeknckmecebkdjeeoglfibojajkbn
Risk Score
3.57
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- NewTab override replaces browser new-tab page, persistent monetization/tracking surface on every new tab.
- Uninstall and install URL hijack both redirect to gameograf.com UTM-tagged URL — traffic harvesting pattern.
- No CSP declared (MV3); innerHTML sinks in popup.js and calendar.js present DOM-XSS risk.
- Extension contacts 12 external JS hosts including Google services and gameograf.com API with no CSP guardrail.
- Low install count (51) with newtab+search override is a tail-attack-surface pattern for future abuse.
Evidence
- newtab_override manifest chrome_url_overrides.newtab set to newtab.html — replaces new tab on every open.
- uninstall_url_hijack crx setUninstallURL targets https://gameograf.com/?utm_source=extension&utm_medium=install
- install_url_hijack crx onInstalled opens https://gameograf.com/?utm_source=extension&utm_medium=install
- no_csp manifest content_security_policy is null; MV3 default applies but no explicit CSP hardening present.
- dom_xss_sinks crx innerHTML assigned from variables in popup.js and calendar.js — DOM-XSS risk without CSP.
- external_js_hosts crx 12 external hosts referenced in JS including api.gameograf.com, mail.google.com, chat.openai.com.
- low_installs_newtab store Only 51 installs with newtab+search override — small-install high-capability anomaly.
- privacy_policy_scoped api Policy fetched; scope_extension=true, data_collection=true, retention=true, third_party_sharing=true.
Permissions Breakdown
- search medium Allows reading/modifying search provider; paired with newtab override raises monetization concern.
- host_permissions: https://api.gameograf.com/* low Scoped to developer's own API domain; limited blast radius.
- chrome_url_overrides.newtab medium Replaces new tab page; monetization vector and persistent user exposure.
Pillar Scores
Permissions4.00
Reputation5.50
Network2.00
Webstore7.00
Maintenance0.00
Privacy0.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 13:18
Listing SHA
f0ca1aa073b3…
Force block
— not fired
Score recovered
no
Elapsed
—