Dodge Challenger SRT Live Wallpaper
ecclghdgdhaincpfojpbonbfgdcbepph
Risk Score
6.08
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- NewTab override with uninstall/install URL hijack — classic traffic-monetization shell pattern.
- Privacy policy is Google's own account policy — not scoped to this extension; admits data collection & 3rd-party sharing.
- No CSP declared (MV3 default only) + innerHTML sinks in popup and calendar JS — DOM-XSS exposure.
- Developer name is empty; verified publisher status partially discounted by monetization-adjacent URL hijack pattern.
- New-tab replacement reaches every user session; combined with missing developer name raises accountability gap.
Evidence
- newtab_override manifest chrome_url_overrides.newtab present — replaces every new tab page.
- uninstall_url_hijack crx setUninstallURL → https://gameograf.com/?utm_source=gameograf&utm_content=uninstall
- install_url_hijack crx onInstalled opens https://gameograf.com/?utm_source=install&utm_content=install
- generic_privacy_policy api Policy is Google account-level policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- dom_xss_sink crx innerHTML assigned from variable in popup.js and calendar.js; no CSP to mitigate.
- no_csp manifest content_security_policy is null; MV3 default applies but no explicit hardening.
- verified_publisher store Verified publisher badge present; discount capped at -1.0 due to monetization URL pattern (v3.5 invariant 0c).
- developer_name_missing store developer_name is empty string — no 'Offered by' accountability signal.
Permissions Breakdown
- search medium Allows reading and potentially manipulating search queries/providers.
- host_permissions: https://api.gameograf.com/* low Scoped to developer's own API domain; limited blast radius.
- chrome_url_overrides.newtab medium Replaces every new tab — persistent high-reach surface for monetization.
Pillar Scores
Permissions3.50
Reputation5.00
Network2.00
Webstore8.50
Maintenance3.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-16 05:30
Listing SHA
8668c7c6355e…
Force block
— not fired
Score recovered
no
Elapsed
—