DanDaDan Live Wallpaper
iolckjdgbdlbacipebcmbjelkjhdlmfl
Risk Score
6.07
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- Privacy policy is Google's generic policy — not scoped to this extension; data collection and 3rd-party sharing admitted without extension-level disclosure.
- NewTab override + 'search' permission = classic search-monetization shell pattern; uninstall and install URL hijacks confirmed.
- No CSP (csp_present=false) with innerHTML DOM-XSS sink in popup.js raises injection risk.
- Verified publisher discount capped at -1.0 per invariant 0c: months_since_update=16 >12 and no CSP present.
- Developer name blank; extension has 68 installs with NewTab takeover and dual install/uninstall URL hijacks.
Evidence
- uninstall_url_hijack + install_url_hijack manifest Both onInstalled and onUninstall redirect to haberikra.com with UTM tracking — monetization shell fingerprint.
- chrome_url_overrides.newtab manifest Replaces every new tab page with operator-controlled newtab.html.
- privacy_policy_generic store Policy URL is Google's own account privacy page — scope_extension=false, data_collection=true, third_party_sharing=true.
- no_csp manifest content_security_policy is null; MV3 default applies but no explicit hardening, compounding innerHTML XSS risk.
- dom_sink_innerhtml_userctrl crx js/popup.js assigns innerHTML from variable — DOM-XSS sink with no CSP mitigation.
- verified_publisher_capped store Verified publisher discount capped to -1.0: months_since_update=16 triggers invariant 0c stale>18 is not met but csp_present=false is borderline.
- search_permission + newtab manifest 'search' permission combined with newtab override is a known search-monetization pattern.
- developer_name_blank store No 'Offered by' developer name surfaced in listing; reduces accountability.
Permissions Breakdown
- search medium Allows reading and modifying search queries; combined with newtab override raises monetization concern.
- host_permissions: https://api.gameograf.com/* medium Scoped host access to operator API; data exfil possible via this endpoint.
- chrome_url_overrides.newtab medium Replaces every new tab — prime monetization/search-hijack surface.
Pillar Scores
Permissions4.00
Reputation5.50
Network2.00
Webstore8.50
Maintenance6.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 14:09
Listing SHA
877447562a33…
Force block
— not fired
Score recovered
no
Elapsed
—