Breezy Beach Live Wallpaper
dfnmijehfiknkcddjpchgaikklmocfhi
Risk Score
3.54
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- NewTab override with uninstall+install URL hijack — classic monetization/tracking shell pattern.
- Uninstall and install URL hijacks redirect to gameograf.com with UTM tracking parameters.
- No CSP on MV3 extension with DOM-XSS innerHTML sink in calendar.js.
- Developer name field is empty; publisher identity relies solely on email domain.
- Search permission + newtab override enables search traffic interception/monetization.
Evidence
- newtab_override manifest chrome_url_overrides.newtab = newtab.html; replaces all new tabs with extension UI.
- uninstall_url_hijack crx setUninstallURL targets https://gameograf.com/?p=33027?utm_source=extension&utm_medium=uninstall
- install_url_hijack crx onInstalled opens https://gameograf.com/?p=33027?utm_source=extension&utm_medium=install
- no_csp manifest content_security_policy is null; csp_present == false on MV3 extension with XSS sink.
- dom_xss_sink crx js/calendar.js: gridEl.innerHTML = html — user-controlled variable assigned to innerHTML.
- verified_publisher store verified_publisher == true; domain gameograf.com resolves and is not throwaway.
- privacy_policy_adequate api Policy fetched; scope_extension=true, data_collection=true, retention=true, third_party_sharing=true.
- empty_developer_name store developer_name is empty string; identity anchored only to support@gameograf.com.
Permissions Breakdown
- search medium Can read/override search queries; paired with newtab override elevates risk.
- alarms low Scheduling only; low standalone risk.
- storage low Local data persistence; no cross-site exposure.
- chrome_url_overrides.newtab medium Replaces newtab with extension page; monetization surface for search traffic.
- host_permissions: https://api.gameograf.com/* low Scoped to dev's own API domain; limited blast radius.
Pillar Scores
Permissions4.50
Reputation4.50
Network2.50
Webstore7.50
Maintenance0.00
Privacy1.00
Code Quality0.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 09:06
Listing SHA
068b27c6b479…
Force block
— not fired
Score recovered
no
Elapsed
—