Yomu Yakadashi Art Live Wallpaper
cfbobdhebljlbkhdhnikebhhijocphfo
Risk Score
5.72
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is on unrelated domain (haberikra.com), admits data collection & 3rd-party sharing, not scoped to this extension → Privacy pillar max.
- Operator cluster of 19+ installs/28 uninstall-URL siblings — factory-pattern NewTab monetization operation.
- Uninstall and install URL hijacks redirect to gameograf.com with UTM tracking on every user lifecycle event.
- NewTab override combined with 'search' permission creates search-monetization attack surface.
- Months since update = 15 (6-12mo band) and tiny install base (46) with no ratings — low-accountability tail extension.
Evidence
- uninstall_url_hijack manifest chrome.runtime.setUninstallURL → gameograf.com with utm_campaign=bg&utm_content=uninstall
- install_url_hijack manifest onInstalled opens gameograf.com with utm_campaign=bg&utm_content=install
- operator_cluster api 6 compound siblings; 19 under same dev email; 28 sharing install URL fingerprint
- privacy_policy_domain_mismatch store Policy at haberikra.com (unrelated domain); scope_extension=false, data_collection=true, third_party_sharing=true
- newtab_override manifest chrome_url_overrides.newtab=newtab.html replaces every new-tab page
- dom_sink_innerhtml_userctrl crx js/popup.js: innerHTML set from variable without CSP — DOM-XSS risk
- csp_absent manifest content_security_policy is null; MV3 default applies but no explicit restriction
- no_developer_name store developer_name is empty string; accountability gap
Permissions Breakdown
- search medium Allows reading/modifying search provider — relevant for NewTab monetization shape.
- host_permissions: https://api.gameograf.com/* low Scoped to developer's own API domain; low blast radius.
- chrome_url_overrides.newtab medium Replaces new-tab page — primary vector for search monetization and tracking.
Pillar Scores
Permissions4.00
Reputation4.50
Network2.00
Webstore9.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Operator Siblings (13)
Other extensions sharing this developer's compound fingerprint:
- kenndofkbpgkfhaecjmnjmehhhbnioeh
- ieepfmpmjnjidennkopcbamjjdemhjcf
- chjbfnbpbgjnofhahgblpcifjcbkolcp
- bpicplogeibhabicoedobpchdkngbhjh
- jmokcnonladmkkdlgbalffkjiogfcgha
- aaobffjniaghknbgjdkigmcnapghemfa
- ckcailiifgopnblmaeaefimdgnaelcph
- dpkgeginpcjfcgnjicpkfkkbnpailidn
- hmagnnippelpfgkmbdnepolcgjlmbohh
- jimikjehahhdekhbmhpbmbponjcimajc
- jofgjibhmlaeofgmidllemkckkpgnpbd
- iimgbphfdpnahafdmikdjnpfnffnbkcl
- gafbkkfalgndkoilabfhmjjjgeihboed
Bookkeeping
Rubric v3.6
Scored at 2026-09-16 04:14
Listing SHA
bad4ee408585…
Force block
— not fired
Score recovered
no
Elapsed
—