Stranger Things Live Wallpaper
cjoflhinifhplhblkimemplnncddfdhf
Risk Score
3.62
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- NewTab override with uninstall/install URL hijack to gameograf.com — classic traffic-monetization shell pattern.
- Two innerHTML DOM-XSS sinks (popup.js, calendar.js) with no CSP present on MV3 extension.
- No developer name listed; developer_name field empty despite verified publisher status.
- Uninstall URL hijack confirmed: chrome.runtime.setUninstallURL() routes to third-party gameograf.com.
- Install URL hijack: onInstalled opens gameograf.com tracking URL with UTM parameters.
Evidence
- newtab_override manifest chrome_url_overrides.newtab = newtab.html — replaces every new tab.
- uninstall_url_hijack crx setUninstallURL to https://gameograf.com/?utm_source=gameograf&utm_medium=link&utm_campaign=bg&utm_content=uninstall
- install_url_hijack crx onInstalled opens https://gameograf.com/?utm_source=install&utm_medium=link&utm_campaign=bg&utm_content=install
- dom_xss_sinks crx innerHTML assigned from variable in popup.js and calendar.js; csp_present=false raises DOM-XSS risk.
- no_csp manifest content_security_policy is null; MV3 has strict default but DOM sinks still exploitable via data.
- verified_publisher store gameograf.com verified publisher; domain resolves, not throwaway, privacy policy scoped and adequate.
- privacy_policy_classification api Policy fetched; scope_extension=true, data_collection=true, retention=true, third_party_sharing=true.
- maintenance_stale store months_since_update=12; falls in 6-12 month band (+3.5).
Permissions Breakdown
- search medium Allows querying/overriding search; paired with newtab override increases search monetization risk.
- chrome_url_overrides.newtab medium Replaces new tab — primary surface for NewTab monetization shells.
- host_permissions: https://api.gameograf.com/* low Scoped to developer's own API domain; limited blast radius.
Pillar Scores
Permissions3.50
Reputation3.50
Network2.00
Webstore6.50
Maintenance3.50
Privacy1.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 06:46
Listing SHA
fa462eaf1223…
Force block
— not fired
Score recovered
no
Elapsed
—