Cat Fireplace Live Wallpaper
dkknccapneifocbigdgokconilihejgk
Risk Score
3.54
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- NewTab override replaces every new tab — high-traffic monetization surface with uninstall/install URL hijacks.
- Uninstall and install URL hijacks redirect to developer site with UTM tracking on every install/removal.
- No developer name listed; 'Offered by' field empty increases accountability gap.
- dom_sink_innerhtml_userctrl in calendar.js without CSP creates DOM-XSS risk.
- search permission combined with NewTab override allows interception of user search queries.
Evidence
- newtab_override manifest chrome_url_overrides.newtab set to newtab.html — replaces every new-tab page for all users.
- uninstall_url_hijack crx setUninstallURL targets https://gameograf.com/?p=32976?utm_source=extension&utm_medium=uninstall
- install_url_hijack crx onInstalled opens https://gameograf.com/?p=32976?utm_source=extension&utm_medium=install
- no_csp manifest content_security_policy is null; MV3 provides defaults but no explicit hardening.
- dom_xss_sink crx innerHTML assigned from variable in js/calendar.js without sanitization.
- verified_publisher store Developer has verified publisher badge; domain gameograf.com resolves, no throwaway signals.
- privacy_policy_adequate api Policy scoped to extension, discloses data collection, retention, and third-party sharing.
- no_developer_name store developer_name field is empty string; 'Offered by' attribution missing.
Permissions Breakdown
- search medium Can read search queries; elevated for a NewTab/wallpaper extension.
- alarms low Schedules background tasks; low standalone risk.
- storage low Persists local settings; standard low-risk API.
- chrome_url_overrides.newtab medium Replaces new-tab page; core vector for traffic monetization.
- host_permissions: https://api.gameograf.com/* low Scoped to developer's own API domain; limited reach.
Pillar Scores
Permissions5.00
Reputation4.00
Network0.00
Webstore8.00
Maintenance0.00
Privacy0.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 06:17
Listing SHA
16a6c3a37d8a…
Force block
— not fired
Score recovered
no
Elapsed
—