One Piece Live Wallpaper - New Tab Theme
gbhmoohcbeeefdeipfcecgdgelfpjoob
Risk Score
3.27
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Uninstall URL hijack and install URL hijack both redirect to gameograf.com with UTM tracking — classic NewTab monetization shell.
- New-tab override replaces browser default page; search permission allows query interception.
- No CSP defined (csp_present=false, MV3); innerHTML DOM-XSS sinks in popup.js and calendar.js without CSP guard.
- Verified publisher discount applies but extension is a low-install NewTab with search override and URL hijacks.
- No developer display name listed in store; 133 installs with 0 ratings limits reputation signal.
Evidence
- uninstall_url_hijack crx setUninstallURL → https://gameograf.com/?utm_source=extension&utm_medium=install (3rd-party redirect).
- install_url_hijack crx onInstalled opens https://gameograf.com/?utm_source=extension&utm_medium=install.
- newtab_override manifest chrome_url_overrides.newtab = newtab.html; replaces every new tab.
- search_permission manifest "search" permission declared on a wallpaper/theme extension.
- no_csp crx content_security_policy is null (csp_present=false) on MV3; innerHTML sinks present.
- dom_xss_sinks crx innerHTML user-controlled assignments in popup.js and calendar.js without CSP mitigation.
- verified_publisher store Publisher verified; domain resolves, not throwaway. Discount applied but capped by URL-hijack signals.
- privacy_policy api Policy fetched; scope_extension=true, data_collection=true, retention=true, third_party_sharing=true → adequate.
Permissions Breakdown
- search medium Allows reading/modifying search queries; medium risk for a NewTab/theme extension.
- host_permissions: https://api.gameograf.com/* low Scoped to developer's own API domain only; low blast radius.
- chrome_url_overrides.newtab medium Replaces new-tab page; primary monetization surface, typical of NewTab shells.
Pillar Scores
Permissions3.50
Reputation3.50
Network2.00
Webstore6.50
Maintenance1.50
Privacy0.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 06:47
Listing SHA
cec124f34471…
Force block
— not fired
Score recovered
no
Elapsed
—