Sanrio Cinnamoroll Halloween Live Wallpaper
cbkaacjfboiijjkojeodihmpldbjndbp
Risk Score
3.45
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- NewTab override with uninstall+install URL hijacks — classic monetization shell pattern scoring +2+2+2 in Webstore.
- No CSP (csp_present=false, MV3) — two innerHTML DOM-XSS sinks in popup.js and calendar.js lack any mitigation.
- Search permission combined with newtab override enables query interception and search monetization.
- Verified publisher but no developer name listed; 72 installs with 0 ratings reduces trust signal value.
- Privacy policy is scoped and adequate, but extension contacts 12 external JS hosts including openai.com and gstatic.com.
Evidence
- newtab_override manifest chrome_url_overrides.newtab = newtab.html; replaces new-tab page — primary monetization surface.
- uninstall_url_hijack crx setUninstallURL targets https://gameograf.com/?utm_source=extension&utm_medium=install (3rd-party).
- install_url_hijack crx onInstalled opens https://gameograf.com/?utm_source=extension&utm_medium=install.
- no_csp manifest content_security_policy is null; MV3 default strict CSP applies but csp_present=false in scan.
- dom_xss_sinks crx innerHTML from variable in js/popup.js and js/calendar.js — XSS risk without CSP.
- verified_publisher store verified_publisher=true; discounts Reputation but no developer name provided.
- external_hosts crx 12 external JS hosts including chat.openai.com, ssl.gstatic.com, multiple Google services.
- privacy_policy_adequate api Policy fetched; scope_extension=true, data_collection=true, retention=true, third_party_sharing=true.
Permissions Breakdown
- search medium Allows reading/manipulating search queries; concerning in a NewTab override context.
- host_permissions: https://api.gameograf.com/* low Scoped to developer-controlled API domain; matches stated wallpaper/data function.
- chrome_url_overrides.newtab medium Replaces new-tab page — primary monetization surface for this category.
Pillar Scores
Permissions3.50
Reputation4.00
Network2.50
Webstore7.00
Maintenance0.00
Privacy0.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 10:58
Listing SHA
62fe8130b0c6…
Force block
— not fired
Score recovered
no
Elapsed
—