Naruto Anime 4K Ultra HD 15 Wallpaper
bmamihpoapicofildgmclopghjandfbj
Risk Score
6.11
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Uninstall URL hijack redirects to gameograf.com ad-tech domain — clear monetization shell behavior.
- Privacy policy is Google's generic account policy, not scoped to this extension; admits data collection and 3rd-party sharing.
- NewTab override with 'search' permission enables search-query interception and ad monetization on every new tab.
- jQuery 1.9.1 bundled with 3 medium CVEs (XSS), version far below fixed_in 3.5.0; no CSP amplifies risk.
- Free-webmail developer (gmail), no verified publisher, no business website — no accountability chain.
Evidence
- uninstall_url_hijack crx chrome.runtime.setUninstallURL to gameograf.com with UTM params — confirmed ad-tech monetization shell.
- privacy_policy_generic store PP URL is myaccount.google.com/privacypolicy — Google's own policy, not scoped to this extension at all.
- newtab_override manifest chrome_url_overrides.newtab = index.html; NewTab hijack with search+topSites is classic monetization vector.
- cve_jquery_1.9.1 crx jquery@1.9.1 carries 3 medium XSS CVEs; no CSP present, amplifying DOM-manipulation risk (×1.5 multiplier).
- free_webmail_developer store Developer email eminearsiz0@gmail.com; no business domain, no verified publisher badge.
- install_url_hijack crx onInstalled opens index.html — install hijack noted; low severity but consistent with shell pattern.
- 12_external_js_hosts crx 12 external JS hosts including gameograf.com, jqueryui.com, popper.js.org — broad external dependency surface.
- no_csp manifest content_security_policy is null; MV3 has defaults but no explicit CSP with vulnerable jquery@1.9.1 is risky.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@1.9.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11023 | jquery@1.9.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@1.9.1 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- search medium Can read and potentially redirect search queries; concerning for a NewTab override.
- topSites medium Exposes user browsing history top sites; combined with NewTab monetization risk.
- unlimitedStorage low Allows unbounded local storage; low standalone risk.
- storage low Standard local storage access; low risk alone.
- chrome_url_overrides.newtab medium Hijacks every new tab; prime real estate for ad-monetization shell patterns.
Pillar Scores
Permissions5.00
Reputation7.50
Network2.50
Webstore10.00
Maintenance1.50
Privacy10.00
Code Quality2.00
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 08:42
Listing SHA
2d108b107239…
Force block
— not fired
Score recovered
no
Elapsed
—