BMW M4 Night Live Wallpaper New Tab
jnfbebhfabncchbalkbebhjmoljleajb
Risk Score
3.74
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- NewTab override replaces every new tab with branded page — high-reach monetization surface.
- Uninstall and install URL hijacks redirect users to developer domain with UTM tracking.
- Two innerHTML DOM-XSS sinks found in popup.js and calendar.js with no CSP guard.
- No CSP defined (MV3 default applies but no explicit policy) — innerHTML sinks unmitigated.
- Developer name absent; verified publisher via gameograf.com domain but no brand display.
Evidence
- newtab_override manifest chrome_url_overrides.newtab=newtab.html replaces every new tab for 10K users.
- uninstall_url_hijack crx setUninstallURL to gameograf.com with UTM params — tracks churn, monetization signal.
- install_url_hijack crx onInstalled opens gameograf.com with UTM install params — engagement funnel.
- dom_sink_innerhtml crx 2x innerHTML sinks in popup.js and calendar.js; no CSP to mitigate XSS.
- no_csp manifest content_security_policy is null; MV3 default applies but no explicit restriction.
- verified_publisher store Verified publisher badge present for gameograf.com; domain resolves, not throwaway.
- privacy_policy_adequate api Policy fetched, scope_extension=true, data_collection=true, retention=true, third_party_sharing=true.
- maintenance_stale store 12 months since last update (Sep 2025); in 6-12mo band (+3.5).
Permissions Breakdown
- search medium Allows reading/modifying search queries; relevant to NewTab but grants search access.
- host_permissions: https://api.gameograf.com/* low Scoped to developer's own API domain only.
- chrome_url_overrides.newtab medium Replaces every new tab page — high reach, monetization surface.
Pillar Scores
Permissions3.00
Reputation3.50
Network2.00
Webstore7.00
Maintenance3.50
Privacy1.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 08:13
Listing SHA
b33b6011f41a…
Force block
— not fired
Score recovered
no
Elapsed
—