Bocchi The Rock Anime Selfie Live Wallpaper
fpfnflkcolpdofjnncipglekhfmdfjnf
Risk Score
3.55
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- NewTab override enables search monetization; paired with 'search' permission and uninstall/install URL hijacks.
- Uninstall and install URL hijacks redirect to gameograf.com with UTM tracking — monetization shell pattern.
- Two innerHTML DOM-XSS sinks with no CSP; MV3 but csp_present==false amplifies code quality risk.
- Developer name absent; no 'Offered by' name increases accountability gap for a NewTab extension.
- Extension contacts 12 external JS hosts including chat.openai.com beyond its stated wallpaper function.
Evidence
- newtab_override manifest chrome_url_overrides.newtab set to newtab.html; replaces every new-tab page for all users.
- uninstall_url_hijack crx setUninstallURL → https://gameograf.com/?utm_source=extension&utm_medium=install (3rd-party redirect).
- install_url_hijack crx onInstalled opens https://gameograf.com/?utm_source=lofi&utm_medium=install (monetization pattern).
- dom_xss_sinks_no_csp crx 2x innerHTML from variable in popup.js and calendar.js; csp_present==false increases XSS exposure.
- broad_js_external_hosts crx 12 external JS hosts incl. chat.openai.com; far beyond wallpaper stated function.
- no_developer_name store developer_name is empty string; no 'Offered by' identity shown in store listing.
- verified_publisher store verified_publisher==true; partial reputation credit applied, capped due to no developer name.
- privacy_policy_adequate api Policy fetched, scope_extension+data_collection+retention+third_party_sharing all true; adequate.
Permissions Breakdown
- search medium Allows reading and manipulating search queries; medium risk for a NewTab/wallpaper extension.
- host_permissions:https://api.gameograf.com/* low Scoped to developer's own API domain; reasonable for wallpaper content fetch.
- chrome_url_overrides.newtab medium Replaces new-tab page; primary monetization surface, enables search hijack.
Pillar Scores
Permissions4.00
Reputation3.50
Network2.00
Webstore7.00
Maintenance1.50
Privacy0.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-16 07:29
Listing SHA
222e1ec76a9c…
Force block
— not fired
Score recovered
no
Elapsed
—