Nissan Skyline GT-R R34 Live Wallpaper
fjigogdcnnemnojaanbmdmkbbhgmfdaa
Risk Score
5.64
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic policy — not scoped to this extension; admits data collection and 3rd-party sharing.
- NewTab override + install/uninstall URL hijack to gameograf.com — clear traffic-monetization shell pattern.
- Developer name is blank; no 'Offered by' identity despite verified_publisher claim.
- DOM-XSS sinks (innerHTML from variables) in calendar.js and popup.js with no CSP in place.
- Uninstall URL hijack redirects users to developer site with UTM tracking on removal.
Evidence
- newtab_override manifest chrome_url_overrides.newtab set to newtab.html — replaces every new tab with developer-controlled page.
- uninstall_url_hijack crx setUninstallURL targets https://gameograf.com/?utm_source=gameograf&utm_medium=link&utm_campaign=bg.
- install_url_hijack crx onInstalled opens https://gameograf.com/?utm_source=install — monetization redirect on install.
- generic_privacy_policy store Policy URL is Google's own privacy policy (myaccount.google.com); scope_extension=false, data_collection=true, third_party_sharing=true.
- no_developer_name store developer_name is empty string; no 'Offered by' identity visible despite verified_publisher=true.
- dom_xss_no_csp crx Two innerHTML-from-variable sinks in calendar.js and popup.js; csp_present=false amplifies XSS risk.
- js_external_hosts_broad crx 12 external JS hosts referenced including Google properties and youtube.com beyond stated wallpaper function.
- maintenance_stale api months_since_update=12 (6–12mo band); install count only 230 — low adoption, moderate staleness.
Permissions Breakdown
- search medium Allows modification of search provider; NewTab override amplifies search monetization risk.
- chrome_url_overrides.newtab high Replaces new-tab page; primary vector for traffic/ad monetization in wallpaper shells.
- host_permissions: https://api.gameograf.com/* medium Outbound calls to developer's own API; scoped but enables data exfiltration to dev server.
Pillar Scores
Permissions5.00
Reputation5.50
Network2.50
Webstore7.50
Maintenance3.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 11:51
Listing SHA
d19fff78ccb6…
Force block
— not fired
Score recovered
no
Elapsed
—