Sad Panda Live Wallpaper
hlacaekdajdgiiofjplpofbgebgjbnco
Risk Score
5.33
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- NewTab override with install/uninstall URL hijack — classic traffic-monetization shell pattern with 7 compound siblings
- Privacy policy URL returns connection error (fetch_error) — treated as no policy, score +10.0
- Operator cluster: 28 siblings by dev email, 7 by compound fingerprint — large-scale wallpaper farm
- Two innerHTML DOM-XSS sinks with no CSP — elevated code quality risk in MV3 context
- No developer display name; manifest uses __MSG__ placeholders obscuring actual title/description
Evidence
- uninstall_url_hijack + install_url_hijack crx Both onInstall and onUninstall redirect to gameograf.com with UTM tracking — monetization shell.
- chrome_url_overrides.newtab manifest Replaces new tab page (newtab.html); paired with search permission = search-monetization risk.
- operator_cluster api 7 compound siblings, 28 siblings by dev email — large NewTab/wallpaper farm under gameograf.com.
- privacy_policy_fetch_error api Privacy policy URL unreachable (ConnectionError); classified as fetched==false → +10.0 privacy.
- dom_sink_innerhtml_userctrl (x2) crx innerHTML sinks in popup.js and calendar.js with no CSP — DOM-XSS risk per FIX B.
- new_tab_override_monetization store NewTab + install/uninstall hijack + search permission = +2.0+3.0+3.0 webstore signals.
- no_developer_name store Developer display name is empty; manifest name is __MSG_appName__ — identity opacity.
- verified_publisher store Verified publisher badge present; -3.0 reputation credit applied (floor 2.0 respected).
Permissions Breakdown
- search medium Allows reading/manipulating search queries; relevant for NewTab/search-override pattern.
- host_permissions: https://api.gameograf.com/* low Scoped to developer's own API domain; expected for a NewTab extension fetching content.
- chrome_url_overrides.newtab medium Replaces new tab page — high-reach monetization surface, counted per v2 rule (a).
Pillar Scores
Permissions3.50
Reputation4.50
Network2.50
Webstore9.00
Maintenance1.50
Privacy10.00
Code Quality4.00
CVE Exposure0.00
Operator Siblings (15)
Other extensions sharing this developer's compound fingerprint:
- fdjpcjggpgdmdikmhoagohakklihimbo
- ammndifopdgpjcpmpbdenfcafipnejlj
- ojhigfemmjpjnmhidflhdlcahgdiiija
- ieocbmlfbinpcffofcjmpbjokkfghodc
- faaegcmakhlmoheamicddkfcmmjoljnd
- amfeinhgbpnnjihjiomibeodnainnjkd
- ceoamfmlgefiljnligpdkdindckojbim
- lcoeefcacppckhidgmkdlnbeajkmeick
- kngkldhmcncemclgjgbbogplfeoppkll
- gfcbimjpmoeofbmnjedjfkemdinagkmp
- kmjgnidfglamdnllpoidpfikcodjapih
- heakmhbelclpalglpiceoocofnkcjefb
- gbeldgdcloiceglhpdnkhbafeoddjehm
- epjpkhahnajkdjjfkeadcgfmfjfgdohf
- fjmlhfejlohohljeioedcliggbfkihdf
Bookkeeping
Rubric v3.6
Scored at 2026-09-16 04:13
Listing SHA
e5ac64306743…
Force block
— not fired
Score recovered
no
Elapsed
—