Lamborghini Aventador SC18 Alston Live Wallpaper
dbomdodikcfpocimcpegpbnlmankljcb
Risk Score
6.14
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- NewTab override with large operator cluster (10 siblings, 38 extensions under same email) — mass-deployment monetization pattern.
- Privacy policy URL fetch failed; policy treated as unavailable — no disclosure of data collection practices.
- Uninstall and install URL hijack both present — tracking user lifecycle events for monetization.
- DOM-XSS sinks (innerHTML) in popup.js and calendar.js with no CSP; elevated injection risk.
- No developer name listed; newtab+search override combo is a known traffic-monetization shell pattern.
Evidence
- operator_cluster_siblings api 38 extensions share same dev email; 10 share full compound fingerprint — large wallpaper/newtab monetization cluster.
- uninstall_url_hijack crx setUninstallURL targets gameograf.com with UTM params — lifecycle tracking confirmed.
- install_url_hijack crx onInstalled opens gameograf.com with UTM install params — install-event monetization.
- privacy_policy_fetch_failed api fetch_error:HTTPError on https://gameograf.com/privacy-policy/ — policy unreadable, scored as unavailable.
- newtab_override manifest chrome_url_overrides.newtab = newtab.html — every new tab replaced; high reach.
- dom_sink_innerhtml_no_csp crx Two innerHTML sinks in popup.js and calendar.js; csp_present==false amplifies DOM-XSS risk.
- no_developer_name store developer_name is empty string; reduces accountability.
- verified_publisher store verified_publisher==true but discount capped: large operator cluster and install/uninstall hijacks indicate monetization shell.
Permissions Breakdown
- search medium Allows reading and modifying search provider; paired with newtab override, raises monetization concern.
- host_permissions: https://api.gameograf.com/* low Scoped to developer's own API domain; limited blast radius.
- chrome_url_overrides.newtab medium Replaces every new tab; high-reach surface for content injection and monetization.
Pillar Scores
Permissions4.00
Reputation4.50
Network2.50
Webstore10.00
Maintenance3.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Operator Siblings (15)
Other extensions sharing this developer's compound fingerprint:
- kbbpgbdclanolnidddbeolaaddllgebp
- kgdahhodabbdnkkphjpneoiadhdphhna
- dihbfoicmibapnfojehonedckdjhegbe
- gfgopigkkjcinmgoancipefafljdfghd
- cdmooeifaodbcailnibfpnmbighehpkj
- pjbnoadhjobchdjkfhpehlbigakbjfii
- iobnmhnecelingbpdadgpmalbdagjbnb
- jpmpdfcaaelghoomjgdebmoekdfkhabp
- ohpdpicjlgbpihginhijhkfdcgfbffgf
- cifonlmfhnimmghojdepepjdgbbminel
- dmdfahkplmikmlboodadelolcmbjgmff
- ckodcbbdgmpjidpfcipfobfagemmfapi
- kbolkhdnpodncbepmdejjijgkdpedgcj
- gfbhidjkgiaopiekkefehamhcmigdcna
- ekmpmfdhakdjaaifkfgpbcagdhlbamki
Bookkeeping
Rubric v3.6
Scored at 2026-09-16 05:07
Listing SHA
1651e574ab7a…
Force block
— not fired
Score recovered
no
Elapsed
—