Dabi Blueflame Live Wallpaper
ekmpmfdhakdjaaifkfgpbcagdhlbamki
Risk Score
5.54
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Operator cluster: 15 compound siblings + 50 dev-email siblings — mass-produced NewTab shell factory.
- Uninstall and install URL hijack both present — confirmed monetization/tracking pattern.
- Privacy policy URL returns HTTP error (fetch_error); policy effectively non-existent.
- NewTab override with search permission = persistent ad-monetization surface on every tab.
- DOM-XSS innerHTML sinks in popup.js and calendar.js with no CSP guard (MV3 but csp_present=false).
Evidence
- operator_cluster_sibling_count_15 api 15 compound siblings share same dev email, install URL, uninstall URL fingerprint — mass-produced NewTab factory.
- uninstall_url_hijack manifest setUninstallURL targets gameograf.com with UTM params — monetization tracking on uninstall.
- install_url_hijack manifest onInstalled opens gameograf.com with UTM params — monetization tracking on install.
- privacy_policy_fetch_error api Privacy policy URL returns HTTPError; fetched=false → scored as no policy (+10.0).
- newtab_override_with_search_permission manifest chrome_url_overrides.newtab + search permission: persistent monetization surface.
- dom_sink_innerhtml_no_csp crx Two innerHTML DOM-XSS sinks in popup.js and calendar.js; csp_present=false amplifies risk.
- verified_publisher_newtab_monetization store Verified publisher but monetization shape (install/uninstall hijack, NewTab) caps discount per v3.5-E.
- no_developer_name store developer_name is empty string; +1.0 reputation penalty.
Permissions Breakdown
- search medium Allows reading/modifying search provider; medium risk on its own.
- host_permissions: https://api.gameograf.com/* low Scoped to developer's own API domain only.
- chrome_url_overrides.newtab medium NewTab override gives persistent monetization surface on every new tab.
Pillar Scores
Permissions4.00
Reputation4.50
Network0.00
Webstore10.00
Maintenance3.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Operator Siblings (15)
Other extensions sharing this developer's compound fingerprint:
- kbbpgbdclanolnidddbeolaaddllgebp
- kgdahhodabbdnkkphjpneoiadhdphhna
- dihbfoicmibapnfojehonedckdjhegbe
- gfgopigkkjcinmgoancipefafljdfghd
- cdmooeifaodbcailnibfpnmbighehpkj
- pjbnoadhjobchdjkfhpehlbigakbjfii
- iobnmhnecelingbpdadgpmalbdagjbnb
- jpmpdfcaaelghoomjgdebmoekdfkhabp
- ohpdpicjlgbpihginhijhkfdcgfbffgf
- cifonlmfhnimmghojdepepjdgbbminel
- dbomdodikcfpocimcpegpbnlmankljcb
- dmdfahkplmikmlboodadelolcmbjgmff
- ckodcbbdgmpjidpfcipfobfagemmfapi
- kbolkhdnpodncbepmdejjijgkdpedgcj
- gfbhidjkgiaopiekkefehamhcmigdcna
Bookkeeping
Rubric v3.6
Scored at 2026-09-16 07:38
Listing SHA
6f3913f65c57…
Force block
— not fired
Score recovered
no
Elapsed
—