Cyberpunk McLaren Live Wallpaper New Tab
iimgbphfdpnahafdmikdjnpfnffnbkcl
Risk Score
5.74
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy URL could not be fetched — no evidence of adequate data handling disclosure.
- Operator cluster of 12+ siblings under same fingerprint signals NewTab monetization farm.
- Uninstall and install URL hijacks redirect to gameograf.com with UTM tracking — monetization shell pattern.
- New-tab override + search permission enables search-query interception and redirect monetization.
- DOM-XSS sink (innerHTML) in popup.js with no CSP elevates XSS risk.
Evidence
- operator_cluster api 12 compound siblings under same dev email/install/uninstall/CSP fingerprint — consistent NewTab monetization cluster.
- uninstall_url_hijack crx chrome.runtime.setUninstallURL → https://gameograf.com/?utm_source=gameograf&utm_medium=link&utm_campaign=bg&utm_content=uninstall
- install_url_hijack crx onInstalled opens https://gameograf.com/?utm_source=install&utm_medium=link&utm_campaign=bg&utm_content=install
- privacy_policy_fetch_failure api Privacy policy URL returns HTTP error; policy could not be evaluated — treated as unfetched.
- newtab_override manifest chrome_url_overrides.newtab set to newtab.html; combined with search permission enables query interception.
- dom_xss_sink crx innerHTML assigned from variable in js/popup.js; no CSP present on MV3 extension.
- no_developer_name store developer_name is empty string; no 'Offered by' identity despite verified_publisher claim.
- maintenance_stale store 15 months since last update — falls in 12-24mo band (+6.0 maintenance).
Permissions Breakdown
- search medium Allows reading/overriding search queries; risky in NewTab context.
- host_permissions: https://api.gameograf.com/* low Scoped to own API domain; low blast radius.
- chrome_url_overrides.newtab medium Replaces new-tab page — primary vector for search monetization.
Pillar Scores
Permissions4.00
Reputation4.50
Network2.50
Webstore8.50
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Operator Siblings (13)
Other extensions sharing this developer's compound fingerprint:
- kenndofkbpgkfhaecjmnjmehhhbnioeh
- ieepfmpmjnjidennkopcbamjjdemhjcf
- chjbfnbpbgjnofhahgblpcifjcbkolcp
- bpicplogeibhabicoedobpchdkngbhjh
- jmokcnonladmkkdlgbalffkjiogfcgha
- aaobffjniaghknbgjdkigmcnapghemfa
- cfbobdhebljlbkhdhnikebhhijocphfo
- ckcailiifgopnblmaeaefimdgnaelcph
- dpkgeginpcjfcgnjicpkfkkbnpailidn
- hmagnnippelpfgkmbdnepolcgjlmbohh
- jimikjehahhdekhbmhpbmbponjcimajc
- jofgjibhmlaeofgmidllemkckkpgnpbd
- gafbkkfalgndkoilabfhmjjjgeihboed
Bookkeeping
Rubric v3.6
Scored at 2026-09-16 06:38
Listing SHA
fb80fa6ba746…
Force block
— not fired
Score recovered
no
Elapsed
—