Los Angeles Lakers Wallpapers New Tab
cfcchgefhpmpeoooenlcgbnleajojhbo
Risk Score
5.58
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- NewTab override with uninstall+install URL hijack — monetization shell pattern.
- Privacy policy is Google's generic policy — does not scope to this extension, but admits data collection and 3rd-party sharing.
- bit.ly affiliate/cloaking hit in js_external_hosts — link redirection obscures destination.
- 16 months since last update with no CSP — stale newtab with open DOM attack surface.
- No developer name listed; missing 'Offered by' identity reduces accountability.
Evidence
- uninstall_url_hijack + install_url_hijack manifest Extension sets uninstall and install redirect URLs to gameograf.com with UTM tracking — monetization shell pattern.
- newtab_override manifest chrome_url_overrides.newtab = index.html — replaces every new tab for all users.
- privacy_policy_generic store Policy URL is Google account policy — scope_extension=false, data_collection=true, third_party_sharing=true.
- affiliate_hit_bit.ly crx bit.ly listed in js_external_hosts — affiliate/cloaking redirector present in extension code.
- dom_sink_innerhtml crx popup.js assigns innerHTML from variable — DOM-XSS sink without CSP protection.
- no_csp manifest content_security_policy is null; csp_present=false — no script source restrictions.
- developer_name_missing store developer_name is empty string — no 'Offered by' identity displayed to users.
- mlionltd.github.io_external_host crx Extension contacts mlionltd.github.io — third-party GitHub Pages host unrelated to stated function.
Permissions Breakdown
- search medium Allows overriding search provider — medium risk for a NewTab extension.
- host_permissions: https://api.gameograf.com/* low Scoped to developer's own API domain; low breadth.
- chrome_url_overrides.newtab medium NewTab override is a monetization surface and replaces user's default page.
Pillar Scores
Permissions4.50
Reputation5.50
Network2.00
Webstore8.00
Maintenance6.00
Privacy10.00
Code Quality0.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 12:33
Listing SHA
871ca19aff4b…
Force block
— not fired
Score recovered
no
Elapsed
—