My Melody Live Wallpaper
dkmkclcinjhocapcmffppjpdcfkcciki
Risk Score
5.53
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- NewTab override with search permission enables full search/ad monetization on every new tab.
- Uninstall and install URL hijacks redirect to operator marketing site (haberikra.com).
- Privacy policy is Google's generic policy — does not scope data collection to this extension.
- No CSP + innerHTML sink (popup.js) creates DOM-XSS exposure.
- months_since_update=15 with no publisher name increases abandonment/transfer risk.
Evidence
- newtab_override manifest chrome_url_overrides.newtab = newtab.html; replaces every new tab page for all 393 users.
- uninstall_url_hijack crx setUninstallURL → https://haberikra.com/?utm_source=gameograf&utm_medium=link&utm_campaign=bg&utm_content=uninstall
- install_url_hijack crx onInstalled opens https://haberikra.com/?utm_source=install&utm_medium=link&utm_campaign=bg&utm_content=install
- privacy_policy_generic api Policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- no_csp manifest content_security_policy is null; MV3 default applies but innerHTML sink still exploitable.
- dom_xss_sink crx js/popup.js: innerHTML assigned from variable with no CSP hardening — DOM-XSS risk.
- newtab_monetization_shape store search permission + newtab override + install/uninstall hijacks match ad-monetization shell pattern.
- developer_name_missing store developer_name is empty string; only email (info@haberikra.com) and verified_publisher=true available.
Permissions Breakdown
- search medium Can override search provider; combined with newtab override enables full search monetization.
- host_permissions: https://api.gameograf.com/* medium Scoped to single domain but enables data exfil to operator-controlled backend.
- chrome_url_overrides.newtab medium Replaces every new tab — high REACH, enables ad/search injection on every new tab open.
Pillar Scores
Permissions4.00
Reputation5.50
Network2.00
Webstore8.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-27 16:20
Listing SHA
fcaf78c14bc5…
Force block
— not fired
Score recovered
no
Elapsed
—