Succubus Academy Live Wallpaper Theme
dmhkdbnopgdobjfijfgdppgoajghhhef
Risk Score
3.55
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- NewTab override with uninstall+install URL hijack redirecting to gameograf.com — monetization shell pattern.
- No CSP on MV3 extension with innerHTML DOM-XSS sinks in popup.js and calendar.js.
- Verified publisher discount capped: no sibling cluster but uninstall/install hijack signals monetization intent.
- New-tab override + search permission = potential search monetization surface.
- Developer name absent from listing; identity accountability reduced.
Evidence
- uninstall_url_hijack + install_url_hijack manifest Both onInstalled and uninstall redirect to gameograf.com UTM URL — monetization shell signal.
- chrome_url_overrides.newtab manifest NewTab override present; combined with search permission creates search-monetization surface.
- csp_present == false manifest No content_security_policy declared on MV3 extension; +2.0 Network per v2 calibration.
- dom_sink_innerhtml_userctrl crx innerHTML sinks in popup.js and calendar.js with no CSP; elevated XSS risk per FIX B.
- verified_publisher store Verified publisher badge present; provides -3.0 Reputation discount floored at 2.0.
- privacy_policy_classification api Policy fetched; scope_extension=true, data_collection=true, retention=true, third_party_sharing=true — adequate.
- js_external_hosts crx 12 external hosts including api.gameograf.com and multiple Google domains; country_count=2 (CA,US).
- developer_name empty store No 'Offered by' developer name in listing; reduces accountability.
Permissions Breakdown
- search medium Allows overriding search provider; medium risk in NewTab context.
- host_permissions: https://api.gameograf.com/* low Scoped to developer's own API domain; limited blast radius.
- chrome_url_overrides.newtab medium Replaces new-tab page; monetization and data-collection surface.
Pillar Scores
Permissions3.50
Reputation3.50
Network2.00
Webstore7.00
Maintenance1.50
Privacy1.00
Code Quality2.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 19:00
Listing SHA
41635692545a…
Force block
— not fired
Score recovered
no
Elapsed
—