Romantic Valentine's Day: Hearts, Roses, and Love Wallpaper
glfomebddkdcndojnhoalkjohbaphiaf
Risk Score
3.90
Risk Level:
Low
Recommendation:
🚫 BLOCK
Top Risks
- Uninstall URL hijacks to gameograf.com—classic monetization shell uninstall redirect.
- Privacy policy is Google's own generic policy; not scoped to this extension at all (+10 privacy).
- NewTab override with search permission = persistent ad-monetization surface on every new tab.
- Three medium-severity jQuery XSS CVEs (v1.9.1); no CSP present on MV3 extension.
- No developer name listed; gameograf.com redirect signals affiliate/monetization operator.
Evidence
- uninstall_url_hijack manifest setUninstallURL targets gameograf.com with UTM params tracking ovkas operator—monetization shell signal.
- newtab_override manifest chrome_url_overrides.newtab=index.html replaces every new tab; paired with search permission.
- privacy_policy_generic store Privacy policy URL is myaccount.google.com/privacypolicy—Google's own policy, not scoped to extension.
- cve_jquery_xss crx jquery@1.9.1 bundled with 3 medium CVEs (CVE-2015-9251, CVE-2019-11358, CVE-2020-11023); fixed_in 3.5.0.
- no_csp manifest content_security_policy is null; no CSP despite bundled vulnerable jQuery.
- no_developer_name store developer_name is empty string; reduces accountability.
- install_url_opens_index manifest install_url_hijack true but target is index.html (internal); low additional risk.
- js_external_hosts_12 crx 12 external JS hosts including gameograf.com, jqueryui.com, crazycraftz.com—broad third-party surface.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@1.9.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11023 | jquery@1.9.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@1.9.1 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- search medium Access to search API; paired with newtab override enables search monetization.
- topSites medium Reads user's most visited sites; privacy-sensitive browsing data.
- unlimitedStorage low No direct data exfil risk but enables persistent local data accumulation.
- storage low Standard local storage; low standalone risk.
- chrome_url_overrides.newtab medium Replaces every new tab page; high-reach persistent monetization surface.
Pillar Scores
Permissions4.00
Reputation6.00
Network4.50
Webstore8.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 08:55
Listing SHA
93ec76c63ead…
Force block
— not fired
Score recovered
no
Elapsed
—