Winx Club live wallpapers
dpkgeginpcjfcgnjicpkfkkbnpailidn
Risk Score
6.28
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- NewTab override by a factory operator (8 sibling extensions) — classic ad-monetization shell pattern.
- Privacy policy hosted on unrelated domain (haberikra.com), not scoped to this extension, admits data collection and third-party sharing.
- Uninstall and install URL hijacking to gameograf.com tracking endpoints — traffic monetization confirmed.
- Operator cluster of 23 dev-email siblings and 41 install-URL siblings indicates mass-production extension farm.
- Privacy policy scope_extension=false + data_collection=true + third_party_sharing=true → maximum privacy risk score.
Evidence
- newtab_override manifest chrome_url_overrides.newtab set to newtab.html — hijacks every new tab for monetization.
- uninstall_url_hijack crx setUninstallURL to gameograf.com with UTM tracking params — 3rd-party traffic redirect on uninstall.
- install_url_hijack crx onInstalled opens gameograf.com with UTM params — 3rd-party redirect on install.
- operator_cluster api 8 compound siblings, 23 dev-email siblings, 41 install-URL siblings — extension factory pattern.
- privacy_policy_mismatch store Policy on haberikra.com (unrelated domain), admits data collection + 3rd-party sharing, not scoped to extension.
- maintenance_stale store 15 months since last update — falls in 12-24mo band (+6.0).
- dom_sink_innerhtml crx innerHTML assigned from variable in popup.js without CSP — DOM-XSS risk.
- verified_publisher_cap store Verified publisher discount capped at -1.0: months_since_update=15 (>12mo stale threshold applies).
Permissions Breakdown
- search medium Allows querying/overriding search; paired with newtab override raises monetization risk.
- chrome_url_overrides.newtab high Replaces every new tab — primary surface for ad-monetization injection.
- host_permissions: https://api.gameograf.com/* low Scoped to developer-controlled domain; no broad host access.
Pillar Scores
Permissions4.00
Reputation5.50
Network2.00
Webstore10.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Operator Siblings (13)
Other extensions sharing this developer's compound fingerprint:
- kenndofkbpgkfhaecjmnjmehhhbnioeh
- ieepfmpmjnjidennkopcbamjjdemhjcf
- chjbfnbpbgjnofhahgblpcifjcbkolcp
- bpicplogeibhabicoedobpchdkngbhjh
- jmokcnonladmkkdlgbalffkjiogfcgha
- aaobffjniaghknbgjdkigmcnapghemfa
- cfbobdhebljlbkhdhnikebhhijocphfo
- ckcailiifgopnblmaeaefimdgnaelcph
- hmagnnippelpfgkmbdnepolcgjlmbohh
- jimikjehahhdekhbmhpbmbponjcimajc
- jofgjibhmlaeofgmidllemkckkpgnpbd
- iimgbphfdpnahafdmikdjnpfnffnbkcl
- gafbkkfalgndkoilabfhmjjjgeihboed
Bookkeeping
Rubric v3.6
Scored at 2026-09-16 05:44
Listing SHA
19c7b0f59c75…
Force block
— not fired
Score recovered
no
Elapsed
—