McLaren P1 Live Wallpaper
jpmpdfcaaelghoomjgdebmoekdfkhabp
Risk Score
5.37
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy URL unreachable (fetch_error) — no verifiable data handling disclosure for a NewTab extension.
- Operator cluster of 34 siblings under same dev email: mass-produced wallpaper/NewTab monetization shell pattern.
- Uninstall and install URL hijacks to gameograf.com UTM links — confirmed monetization shell behaviour.
- NewTab override + search permission enables search query capture and ad-revenue redirection on every new tab.
- Two innerHTML DOM-XSS sinks with no CSP present — content injected into new tab could be exploited.
Evidence
- operator_cluster_large api 34 siblings share dev email; 7 share full compound fingerprint — mass-produced NewTab shell factory.
- uninstall_url_hijack manifest setUninstallURL → https://gameograf.com/?utm_source=gameograf&utm_medium=link&utm_campaign=bg&utm_content=uninstall
- install_url_hijack manifest onInstalled opens https://gameograf.com/?utm_source=install&utm_medium=link&utm_campaign=bg&utm_content=install
- privacy_policy_fetch_error api privacy_policy_classification.fetched==false; HTTPError — policy unverifiable, scored +10.0.
- newtab_override manifest chrome_url_overrides.newtab set to newtab.html; combined with search permission raises monetization concern.
- dom_xss_no_csp crx Two innerHTML sinks in popup.js and calendar.js; csp_present==false amplifies DOM-XSS risk to +2.0.
- no_developer_name store developer_name is empty string; reduces accountability signal.
- verified_publisher store verified_publisher==true but discount capped: privacy policy unreachable and monetization URL hijacks present.
Permissions Breakdown
- search medium Allows reading/manipulating search queries; paired with NewTab override amplifies search monetization risk.
- chrome_url_overrides.newtab high Replaces every new tab — prime real estate for search hijacking and ad monetization.
- host_permissions: https://api.gameograf.com/* low Scoped to own API domain; acceptable for wallpaper data fetch but enables data exfil.
Pillar Scores
Permissions5.00
Reputation4.00
Network2.50
Webstore9.00
Maintenance3.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Operator Siblings (15)
Other extensions sharing this developer's compound fingerprint:
- kbbpgbdclanolnidddbeolaaddllgebp
- kgdahhodabbdnkkphjpneoiadhdphhna
- dihbfoicmibapnfojehonedckdjhegbe
- gfgopigkkjcinmgoancipefafljdfghd
- cdmooeifaodbcailnibfpnmbighehpkj
- pjbnoadhjobchdjkfhpehlbigakbjfii
- iobnmhnecelingbpdadgpmalbdagjbnb
- ohpdpicjlgbpihginhijhkfdcgfbffgf
- cifonlmfhnimmghojdepepjdgbbminel
- dbomdodikcfpocimcpegpbnlmankljcb
- dmdfahkplmikmlboodadelolcmbjgmff
- ckodcbbdgmpjidpfcipfobfagemmfapi
- kbolkhdnpodncbepmdejjijgkdpedgcj
- gfbhidjkgiaopiekkefehamhcmigdcna
- ekmpmfdhakdjaaifkfgpbcagdhlbamki
Bookkeeping
Rubric v3.6
Scored at 2026-09-16 04:54
Listing SHA
2ecbb9b966d1…
Force block
— not fired
Score recovered
no
Elapsed
—