DOOM The Dark Ages Wallpapers
ihjbdbhnanglcpgoobmlojmfjlbnlkgk
Risk Score
5.57
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- NewTab override with search permission = classic search-monetization shell; install + uninstall URL hijacks confirmed.
- Privacy policy is Google's generic policy (not scoped to this extension), yet data_collection and third_party_sharing are true — scores as worst-case.
- Uninstall and install URL hijacking to gameograf.com tracking URLs — behavioral monetization evidence.
- External JS host mlionltd.github.io is an uncontrolled third-party GitHub Pages domain — supply-chain risk.
- No CSP + innerHTML user-controlled sink in popup.js raises DOM-XSS risk surface.
Evidence
- newtab_override manifest chrome_url_overrides.newtab = index.html; replaces new-tab page entirely.
- install_uninstall_hijack manifest Both onInstalled and uninstall URLs redirect to gameograf.com with UTM tracking params.
- generic_privacy_policy store Privacy policy URL is Google's own account policy — not scoped to this extension; data_collection+third_party_sharing true.
- external_uncontrolled_host crx js_external_hosts includes mlionltd.github.io — third-party GitHub Pages, not developer-controlled.
- no_csp manifest content_security_policy is null; MV3 default applies but no explicit restriction declared.
- dom_xss_sink crx innerHTML assigned from variable in js/popup.js with no CSP guard — DOM-XSS risk.
- search_permission_newtab_combo manifest search permission + newtab override = monetization-pattern fingerprint.
- stale_16mo store Last updated May 2025; months_since_update=16 → maintenance score elevated.
Permissions Breakdown
- search medium Allows override of browser search; paired with NewTab override amplifies search-monetization risk.
- host_permissions: https://api.gameograf.com/* low Scoped to developer's own API domain; limited blast radius.
- chrome_url_overrides.newtab medium Replaces new-tab page; primary vector for ad/search monetization.
Pillar Scores
Permissions3.30
Reputation5.00
Network2.00
Webstore8.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 05:50
Listing SHA
793bf7e2ed89…
Force block
— not fired
Score recovered
no
Elapsed
—