Disney Princess Live Wallpaper
healopdbnfaejienbcdibohhjdcejica
Risk Score
5.86
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Brand impersonation: uses 'Disney' branding without confirmed ownership (confirmed_owner=false).
- Privacy policy is Google's own policy — not scoped to this extension; admits data collection and 3rd-party sharing.
- Uninstall and install URL hijacks redirect to gameograf.com with UTM tracking; monetization shell pattern.
- New-tab override + search permission = classic search-monetization vector.
- bit.ly affiliate/cloaking hit in js_external_hosts; short-link redirector obscures real destination.
Evidence
- brand_impersonation store brand_mention: brands=['disney'], confirmed_owner=false, is_impersonation=true; dev domain is gameograf.com.
- privacy_policy_generic store Policy URL is myaccount.google.com/privacypolicy — Google's own policy, scope_extension=false, data_collection=true, third_party_sharing=true.
- uninstall_url_hijack crx chrome.runtime.setUninstallURL -> gameograf.com with UTM params (bg/uninstall campaign).
- install_url_hijack crx onInstalled opens gameograf.com with UTM params (bg/install campaign).
- newtab_override manifest chrome_url_overrides.newtab = newtab.html; combined with 'search' permission = monetization shell.
- affiliate_hit crx js_external_hosts includes bit.ly — flagged as affiliate/cloaking redirector by threat_intel.
- verified_publisher_stale store Verified publisher but months_since_update=16 (>18mo threshold not yet met, but monetization signals cap discount per v3.5-E).
- no_csp manifest csp_present=false; MV3 default CSP applies but no explicit CSP declared; no CVEs so no amplifier.
Permissions Breakdown
- search medium Allows search-provider integration; paired with newtab override elevates risk of search hijack.
- chrome_url_overrides.newtab medium Replaces new-tab page; core mechanism for monetization shells and search redirect.
Pillar Scores
Permissions3.50
Reputation6.50
Network2.50
Webstore9.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 07:24
Listing SHA
002bfff82bba…
Force block
— not fired
Score recovered
no
Elapsed
—