cfkkdamfechdeemgmgbbilmjhkcjmdhp
cfkkdamfechdeemgmgbbilmjhkcjmdhp
Risk Score
4.44
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Uninstall and install URL hijack both flagged with null targets — classic traffic-monetization shell pattern.
- Privacy policy is generic Google account policy, not scoped to this extension; scope_extension=false with data_collection+third_party_sharing=true → max privacy risk.
- Extension title and description are unresolved i18n keys (__MSG_*) — no verifiable identity or function.
- No developer name, email, or verifiable domain; js_external_hosts points to gameograf.com indicating possible game-portal shell.
- Extension is essentially empty (no permissions, no host access, no content scripts) yet contacts external host gameograf.com.
Evidence
- install_url_hijack + uninstall_url_hijack both true manifest Both onInstalled and uninstall hooks fire to external URLs (targets null/not extractable) — monetization shell indicator.
- js_external_hosts: gameograf.com crx External JS host gameograf.com detected; game-portal shell pattern association.
- Generic Google privacy policy store Policy URL is myaccount.google.com/privacypolicy; scope_extension=false, data_collection=true, third_party_sharing=true — generic/unscoped.
- No developer identity store developer_name, developer_email, and developer_domain all empty/null; no verified publisher badge.
- Empty manifest with external host manifest Zero permissions, host_permissions, and content_scripts_matches declared; 2 JS files still reference gameograf.com.
- Unresolved i18n manifest name/description manifest manifest_name=__MSG_appName__, manifest_description=__MSG_appDesc__; true function unverifiable.
- No CSP declared manifest content_security_policy is null; MV3 has default CSP but explicit absence noted alongside external host.
- Game-portal shell fingerprint crx operator_cluster fingerprint contains gameograf.com; combined with URL hijacks matches game-portal monetization shell.
Pillar Scores
Permissions0.00
Reputation8.50
Network0.00
Webstore8.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 12:21
Listing SHA
c53aae183306…
Force block
— not fired
Score recovered
no
Elapsed
—