Furry Lofi Study Break Live Wallpaper
jgpbfkndicgcihpdaabjhofbapemadai
Risk Score
6.07
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- Google's privacy policy used as extension policy — admits data collection and 3rd-party sharing without scoping to this extension.
- NewTab override + search permission creates search-interception / monetization surface on every new tab.
- Install and uninstall URL hijack to gameograf.com with UTM tracking — confirmed monetization shell behavior.
- No developer name listed; policy URL is generic Google policy not authored by this developer.
- Two DOM-XSS innerHTML sinks with no CSP, increasing exploitability if extension data sources are compromised.
Evidence
- privacy_policy_generic store Policy URL is Google's own account policy (myaccount.google.com); scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 Privacy (v3.5-D).
- newtab_override manifest chrome_url_overrides.newtab set to newtab.html — NewTab monetization shape, +2.0 Webstore.
- install_uninstall_hijack crx uninstall_url_hijack=true and install_url_hijack=true both pointing to gameograf.com with UTM params. +3.0+2.0 Webstore.
- no_developer_name store developer_name is empty string; +1.0 Reputation for missing 'Offered by'.
- dom_xss_sinks_no_csp crx Two innerHTML-userctrl sinks in calendar.js and popup.js; csp_present=false → +2.0 Code Quality (FIX B).
- stale_12_to_24mo store months_since_update=13 → Maintenance +6.0 (6-12mo band edge; actually 13mo falls in 12-24mo band → +6.0).
- no_csp_mv3 manifest content_security_policy is null; MV3 has strict default but no explicit CSP raises innerHTML-sink exploitability.
- js_external_hosts_12_domains crx 12 external JS hosts spanning Google services + gameograf.com; >3 distinct registrable domains → +1.5 Network.
Permissions Breakdown
- search medium Allows querying the browser's search API; combined with NewTab override elevates search interception risk.
- chrome_url_overrides.newtab high Replaces every new tab — primary monetization vector for wallpaper shells.
- host_permissions: https://api.gameograf.com/* low Scoped to dev-controlled domain only; acceptable for extension API calls.
Pillar Scores
Permissions5.00
Reputation6.50
Network2.00
Webstore7.50
Maintenance6.00
Privacy10.00
Code Quality4.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-16 07:04
Listing SHA
0fd7d9026cc9…
Force block
— not fired
Score recovered
no
Elapsed
—