Ponyo Wallpapers
bnmobfhfbagiomlphadlgdakbkfehnke
Risk Score
5.56
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Google's own privacy policy used — completely unscoped to this extension, admits data collection and 3rd-party sharing.
- New-tab override with uninstall URL hijack and install URL hijack — classic monetization shell pattern.
- bit.ly affiliate/cloaking link in external JS hosts — cloaked redirect destination unverifiable.
- mlionltd.github.io as external JS host — third-party GitHub Pages domain with no clear ownership.
- No developer name listed and privacy policy is Google's generic policy, not extension-specific.
Evidence
- privacy_policy_generic_google store Policy URL is myaccount.google.com/privacypolicy — Google's own policy, scope_extension=false, data_collection=true, third_party_sharing=true.
- newtab_override_with_monetization_hijacks manifest chrome_url_overrides.newtab=index.html; uninstall_url_hijack and install_url_hijack both true pointing to gameograf.com UTM URLs.
- affiliate_hit_bitly crx bit.ly in js_external_hosts — affiliate/cloaking redirector per threat_intel.affiliate_hits.
- external_host_github_pages crx mlionltd.github.io in js_external_hosts — uncontrolled third-party GitHub Pages domain.
- dom_xss_sink crx dom_sink_innerhtml_userctrl in js/popup.js with no CSP — elevated DOM-XSS risk.
- no_developer_name store developer_name is empty string; verified_publisher=true but no displayed name.
- maintenance_stale store months_since_update=14 falls in 12-24mo band (+6.0 maintenance score).
- no_csp manifest content_security_policy is null; MV3 provides defaults but dom_sink_innerhtml_userctrl is higher risk without explicit CSP.
Permissions Breakdown
- search medium Allows querying/overriding search; combined with newtab override raises monetization risk.
- chrome_url_overrides.newtab high Replaces every new tab — primary surface for ad/search monetization shells.
- host_permissions: https://api.gameograf.com/* low Scoped to dev-controlled API domain; limited blast radius.
Pillar Scores
Permissions4.00
Reputation5.50
Network2.50
Webstore7.50
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 06:02
Listing SHA
88c550b44e56…
Force block
— not fired
Score recovered
no
Elapsed
—