Digital Gaze Live Wallpaper
dccgjjinkhjipbefmhpjkpelhgmfilnj
Risk Score
5.63
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy URL returned HTTP error (fetch_error); policy unverifiable — scored as no policy (+10.0).
- NewTab override with search permission and uninstall/install URL hijacks — classic monetization shell pattern.
- Uninstall URL hijack redirects to gameograf.com with UTM tracking; install URL hijack also present.
- No CSP declared (MV3, so no MV2 penalty, but innerHTML sinks lack mitigations).
- Developer name field empty; no 'Offered by' display name reduces accountability.
Evidence
- privacy_policy_fetch_failed api Privacy policy at gameograf.com/privacy-policy/ returned HTTPError; scored as fetched==false → +10.0 Privacy.
- newtab_override manifest chrome_url_overrides.newtab = newtab.html; NewTab monetization pattern with search permission.
- uninstall_url_hijack crx setUninstallURL to gameograf.com with UTM params; install redirect also present → +2.0+2.0 Webstore.
- no_developer_name store developer_name is empty string; reduces accountability, +1.0 Reputation.
- dom_sink_innerhtml crx Two innerHTML-from-variable sinks in popup.js and calendar.js; no CSP present → +2.0 Code Quality each capped.
- verified_publisher store Extension has verified_publisher=true; -3.0 Reputation discount applied (floor 2.0).
- cve_findings_empty api No CVEs found in bundled libs (jquery 3.7.1 is current/safe); CVE pillar = 0.0.
- wayback_no_ownership_change api No ownership change detected; domain age 2051 days, not new; no bad host hits.
Permissions Breakdown
- search medium Can modify search provider behavior; combined with newtab override increases monetization risk.
- chrome_url_overrides.newtab medium Replaces new-tab page; primary monetization surface for this category of extension.
- host_permissions: https://api.gameograf.com/* low Scoped to developer's own API domain; low blast radius but enables data exfiltration to dev.
Pillar Scores
Permissions5.00
Reputation4.00
Network2.00
Webstore7.50
Maintenance3.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-16 05:43
Listing SHA
a64639a4f07a…
Force block
— not fired
Score recovered
no
Elapsed
—