Goku Dragon Ball Live Wallpaper
dndclnmdciilnjcpjkdkkhcbdakejnbm
Risk Score
3.39
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Uninstall URL hijack + install URL hijack: both route to gameograf.com tracking URLs (utm params).
- NewTab override with 'search' permission: classic monetization shell pattern capturing user searches.
- No CSP defined (MV3 still has null content_security_policy) combined with innerHTML DOM-XSS sink in calendar.js.
- No developer name supplied; verified publisher badge present but name field empty.
- Small install base (442) with newtab override and search permission is a tail-attack-surface pattern.
Evidence
- uninstall_url_hijack manifest setUninstallURL targets https://gameograf.com/?p=32884?utm_source=extension&utm_medium=uninstall
- install_url_hijack manifest onInstalled opens https://gameograf.com/?p=32884?utm_source=extension&utm_medium=install
- newtab_override manifest chrome_url_overrides.newtab set to newtab.html; search permission also declared.
- csp_absent crx content_security_policy is null; MV3 default applies but no explicit policy hardening.
- dom_xss_sink crx js/calendar.js: gridEl.innerHTML = html — user-controlled variable written to innerHTML.
- verified_publisher store gameograf.com is verified publisher; discount applied but capped due to monetization signals.
- privacy_policy_adequate api Policy fetched; scope_extension=true, data_collection=true, retention=true, third_party_sharing=true.
- no_developer_name store developer_name field is empty string despite verified_publisher flag.
Permissions Breakdown
- search medium Access to search queries; paired with newtab override raises monetization risk.
- alarms low Schedules background tasks; low standalone risk.
- storage low Local data persistence only.
- host_permissions: https://api.gameograf.com/* medium Scoped to developer's own API; allows data exfil to dev-controlled endpoint.
- chrome_url_overrides.newtab medium Replaces new-tab page; monetization surface, search hijack vector.
Pillar Scores
Permissions4.30
Reputation3.00
Network2.00
Webstore7.00
Maintenance0.00
Privacy1.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 15:40
Listing SHA
2ac1d8797cf3…
Force block
— not fired
Score recovered
no
Elapsed
—