Max Verstappen Red Bull F1 Champion Maserati Live Wallpaper
ejomlpbekmhokbcbjpgicekkkagnckfl
Risk Score
3.61
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- NewTab override + search permission enables ad/search monetization on every new tab.
- Uninstall and install URL hijacks redirect users to developer site for tracking.
- Two innerHTML DOM-XSS sinks (popup.js, calendar.js) with no CSP to mitigate.
- Developer name field is empty, reducing accountability signals.
- No CSP on MV3 extension with DOM-sink findings amplifies XSS exposure.
Evidence
- newtab_override manifest chrome_url_overrides.newtab set to newtab.html; high-reach monetization surface on every new tab.
- uninstall_url_hijack crx setUninstallURL to https://gameograf.com/?utm_source=gameograf&utm_medium=link&utm_campaign=bg&utm_content=uninstall
- install_url_hijack crx onInstalled opens https://gameograf.com/?utm_source=install&utm_medium=link&utm_campaign=bg&utm_content=install
- dom_sink_innerhtml_userctrl crx Two innerHTML assignments from variables found in popup.js and calendar.js; no CSP to block exploitation.
- verified_publisher store Extension has verified publisher badge; developer domain gameograf.com resolves and is not throwaway.
- no_csp manifest content_security_policy is null; MV3 provides some default but DOM sinks are unmitigated by explicit CSP.
- privacy_policy_adequate api Policy fetched; scope_extension=true, data_collection=true, retention=true, third_party_sharing=true, third_party_silence=false.
- search_permission_newtab manifest search permission + newtab override is a common ad-monetization pattern for wallpaper/theme extensions.
Permissions Breakdown
- search medium Allows reading/manipulating search queries; combined with newtab override raises monetization risk.
- host_permission: https://api.gameograf.com/* low Scoped to developer's own API domain; limited blast radius.
- chrome_url_overrides.newtab medium Replaces every new tab; high-reach surface for ad/search monetization.
Pillar Scores
Permissions3.50
Reputation3.50
Network2.00
Webstore6.50
Maintenance3.50
Privacy1.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 08:52
Listing SHA
402dd530bb03…
Force block
— not fired
Score recovered
no
Elapsed
—