Hello Kitty Pixel Art Live Wallpaper
ckcailiifgopnblmaeaefimdgnaelcph
Risk Score
4.54
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- NewTab override + search permission: classic ad-monetization wallpaper shell with 7 sibling extensions under same fingerprint.
- Privacy policy is Google's own generic policy — not scoped to this extension; data_collection and third_party_sharing admitted.
- Uninstall and install URL hijack: both redirect to gameograf.com UTM-tracked endpoints.
- Operator cluster of 22 extensions under same dev email / 40 under same install URL pattern — mass-production shell indicator.
- 16-month staleness + no CSP + innerHTML DOM-XSS sink in popup.js with no mitigating controls.
Evidence
- newtab_override manifest chrome_url_overrides.newtab = newtab.html; paired with search permission — monetization shell pattern.
- uninstall_url_hijack crx setUninstallURL targets https://gameograf.com with UTM params — 3rd-party redirect on uninstall.
- install_url_hijack crx onInstalled opens https://gameograf.com with UTM params — engagement-tracking redirect.
- operator_cluster store 7 compound siblings; 22 extensions share dev email; 40 share install URL — mass-production operator.
- privacy_policy_generic api Policy URL is Google's own account policy (456KB), not scoped to this extension; data_collection=true, third_party_sharing=true.
- dom_xss_sink crx innerHTML set from variable in js/popup.js with no CSP and no sanitization — DOM-XSS risk.
- no_developer_name store developer_name is empty string; verified_publisher present but no display name reduces accountability.
- stale_16mo store Last updated May 2025 but months_since_update=16 implies scoring at ~Sep 2026; 12-24mo band applies.
Permissions Breakdown
- search medium Allows overriding search provider; medium-impact in context of NewTab override.
- host_permissions: https://api.gameograf.com/* low Scoped to developer's own API domain; limited blast radius.
- chrome_url_overrides.newtab medium Replaces new-tab page; monetization/ad-injection vector for wallpaper shell.
Pillar Scores
Permissions4.00
Reputation5.00
Network2.00
Webstore9.50
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Operator Siblings (13)
Other extensions sharing this developer's compound fingerprint:
- kenndofkbpgkfhaecjmnjmehhhbnioeh
- ieepfmpmjnjidennkopcbamjjdemhjcf
- chjbfnbpbgjnofhahgblpcifjcbkolcp
- bpicplogeibhabicoedobpchdkngbhjh
- jmokcnonladmkkdlgbalffkjiogfcgha
- aaobffjniaghknbgjdkigmcnapghemfa
- cfbobdhebljlbkhdhnikebhhijocphfo
- dpkgeginpcjfcgnjicpkfkkbnpailidn
- hmagnnippelpfgkmbdnepolcgjlmbohh
- jimikjehahhdekhbmhpbmbponjcimajc
- jofgjibhmlaeofgmidllemkckkpgnpbd
- iimgbphfdpnahafdmikdjnpfnffnbkcl
- gafbkkfalgndkoilabfhmjjjgeihboed
Bookkeeping
Rubric v3.6
Scored at 2026-09-16 05:43
Listing SHA
7397d1e363bb…
Force block
— not fired
Score recovered
no
Elapsed
—