Fortnite Venom Live Wallpaper
hdkielnmbndkingoimclciemhmeolkfb
Risk Score
5.71
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy URL returns HTTP error (unfetchable) — effectively no policy for a NewTab extension.
- Brand impersonation: 'Fortnite' branded by unconfirmed developer gameograf.com.
- Uninstall + install URL hijack both active — classic traffic-monetization shell pattern.
- NewTab override with search permission and install/uninstall tracking hooks.
- innerHTML DOM-XSS sink in popup.js with no CSP present on MV3.
Evidence
- privacy_policy_unfetchable api Privacy policy at haberikra.com/privacy-policy/ returned HTTPError; treated as no policy.
- brand_impersonation store brand_mention.is_impersonation=true for 'fortnite'; developer gameograf.com not a confirmed owner.
- uninstall_url_hijack crx chrome.runtime.setUninstallURL targets gameograf.com with UTM params.
- install_url_hijack crx onInstalled opens gameograf.com with UTM install tracking.
- newtab_override manifest chrome_url_overrides.newtab = newtab.html; monetization shell pattern with search permission.
- dom_xss_sink crx innerHTML user-controlled assignment in popup.js; no CSP present.
- no_developer_name store developer_name is empty string; reduces accountability.
- stale_15mo store Last updated June 2025 but months_since_update=15; 6-12mo band applies (+3.5 maintenance).
Permissions Breakdown
- search medium Allows reading/overriding search queries; meaningful for a NewTab monetization shell.
- host_permissions: https://api.gameograf.com/* low Scoped to developer's own API domain only.
- chrome_url_overrides.newtab medium Replaces new-tab page; primary monetization vector for wallpaper/shell extensions.
Pillar Scores
Permissions3.50
Reputation6.50
Network2.00
Webstore8.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 06:52
Listing SHA
7b03892de443…
Force block
— not fired
Score recovered
no
Elapsed
—