PS5 Pro Chip Live Wallpaper
ieocbmlfbinpcffofcjmpbjokkfghodc
Risk Score
5.09
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy URL returns connection error — effectively no accessible policy; score treated as fetched=false (+10.0).
- NewTab override (newtab.html) with install+uninstall URL hijack to gameograf.com — monetization shell pattern.
- Operator cluster: 3+ sibling extensions under same fingerprint; 13 siblings by dev_email — coordinated publisher.
- No CSP (MV3 mitigates slightly) + two innerHTML DOM-XSS sinks in popup.js and calendar.js.
- No developer display name; verified_publisher but no accessible privacy policy, uninstall/install URL redirect.
Evidence
- privacy_policy_fetch_failed api privacy_policy_classification.fetched=false (ConnectionError); treated as no accessible policy → Privacy pillar +10.0.
- uninstall_url_hijack crx uninstall_url_hijack=true → gameograf.com/?utm_source=extension&utm_medium=install; Webstore +3.0.
- install_url_hijack crx install_url_hijack=true → same UTM URL; Webstore +2.0.
- newtab_override manifest chrome_url_overrides.newtab=newtab.html; search permission present; monetization-shape NewTab.
- operator_cluster api sibling_count=3 compound; dev_email shared by 13 extensions → coordinated publisher cluster; Webstore +2.5.
- dom_xss_sink crx Two dom_sink_innerhtml_userctrl findings (popup.js, calendar.js); no CSP → Code Quality +2.0 each applied once.
- no_developer_name store developer_name is empty string; Reputation +1.0.
- verified_publisher store verified_publisher=true → Reputation -3.0; cap applied (monetization signals trigger 0c, floor at 2.0).
Permissions Breakdown
- search medium Allows querying the browser search API; concerning paired with newtab override.
- host_permissions: https://api.gameograf.com/* low Scoped to developer's own API domain; limited blast radius.
- chrome_url_overrides.newtab medium Replaces new-tab page; high daily-reach surface for monetization or data collection.
Pillar Scores
Permissions4.00
Reputation4.50
Network2.00
Webstore8.50
Maintenance1.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Operator Siblings (15)
Other extensions sharing this developer's compound fingerprint:
- fdjpcjggpgdmdikmhoagohakklihimbo
- ammndifopdgpjcpmpbdenfcafipnejlj
- ojhigfemmjpjnmhidflhdlcahgdiiija
- faaegcmakhlmoheamicddkfcmmjoljnd
- amfeinhgbpnnjihjiomibeodnainnjkd
- ceoamfmlgefiljnligpdkdindckojbim
- hlacaekdajdgiiofjplpofbgebgjbnco
- lcoeefcacppckhidgmkdlnbeajkmeick
- kngkldhmcncemclgjgbbogplfeoppkll
- gfcbimjpmoeofbmnjedjfkemdinagkmp
- kmjgnidfglamdnllpoidpfikcodjapih
- heakmhbelclpalglpiceoocofnkcjefb
- gbeldgdcloiceglhpdnkhbafeoddjehm
- epjpkhahnajkdjjfkeadcgfmfjfgdohf
- fjmlhfejlohohljeioedcliggbfkihdf
Bookkeeping
Rubric v3.6
Scored at 2026-09-15 14:17
Listing SHA
ed62473b1dbb…
Force block
— not fired
Score recovered
no
Elapsed
—