Swordsman of the Azure Blade Live Wallpaper
hdiolefhcknlpfpeihnmcanemiopbaef
Risk Score
3.47
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- NewTab override replaces every new tab; hijacks user's default start page for monetization.
- Uninstall and install URL hijacks send user to gameograf.com tracking URLs on extension lifecycle events.
- No developer name listed; reduced accountability for a newtab-class extension.
- DOM-XSS sink (innerHTML from variable) in calendar.js without CSP; potential XSS vector.
- search permission + newtab override is a common search-monetization pattern.
Evidence
- newtab_override manifest chrome_url_overrides.newtab set to newtab.html; every new tab replaced by extension.
- uninstall_url_hijack crx setUninstallURL -> https://gameograf.com/?p=32943?utm_source=extension&utm_medium=uninstall
- install_url_hijack crx onInstalled opens https://gameograf.com/?p=32943?utm_source=extension&utm_medium=install
- no_developer_name store developer_name field is empty; reduced accountability.
- dom_xss_sink crx innerHTML assigned from variable in js/calendar.js; no CSP to mitigate DOM-XSS.
- csp_absent manifest content_security_policy is null; MV3 default applies but no explicit hardening.
- verified_publisher store verified_publisher=true; domain resolves, policy scoped — partially mitigates reputation risk.
- privacy_policy_complete api Policy fetched; scope_extension, data_collection, retention, third_party_sharing all true.
Permissions Breakdown
- search medium Access to search provider settings; enables search override behavior.
- alarms low Scheduled tasks only; low standalone risk.
- storage low Local data persistence; no data exfil on its own.
- chrome_url_overrides.newtab medium Replaces every new tab with extension content; broad monetization surface.
- host_permissions: https://api.gameograf.com/* medium Scoped to developer's own API domain; enables data send/receive.
Pillar Scores
Permissions3.50
Reputation3.50
Network2.00
Webstore7.50
Maintenance0.00
Privacy0.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 07:30
Listing SHA
500ff9e9cd34…
Force block
— not fired
Score recovered
no
Elapsed
—