Elden Ring Erdtree Live Wallpaper
kagfpcjflolcidmapkbkllpaibhinppi
Risk Score
5.78
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Google's generic privacy policy linked — not scoped to this extension; admits data collection and third-party sharing.
- NewTab override + search permission = monetization shell pattern; installs/uninstall URL hijack to gameograf.com.
- Same developer email (support@gameograf.com) fingerprinted across 12 other extensions — factory pattern.
- No developer name listed; brand identity unverifiable.
- DOM innerHTML sinks in calendar.js and popup.js with no CSP — XSS attack surface if API data is untrusted.
Evidence
- newtab_override manifest chrome_url_overrides.newtab set; combined with 'search' permission indicates search-monetization shape.
- uninstall_url_hijack crx setUninstallURL targets https://gameograf.com with UTM tracking params.
- install_url_hijack crx onInstalled opens https://gameograf.com with UTM install tracking params.
- privacy_policy_generic store Privacy URL is Google's own policy (myaccount.google.com/privacypolicy); scope_extension=false, data_collection=true, third_party_sharing=true.
- operator_cluster_email api support@gameograf.com shares fingerprint with 12 other extensions by dev_email dimension.
- no_developer_name store developer_name is empty string; identity unverifiable.
- dom_xss_sink_no_csp crx innerHTML assignments in calendar.js and popup.js; csp_present=false on MV3 extension.
- maintenance_stale store 13 months since last update; 6-12mo band (+3.5) but crosses into 12-24mo band (+6.0).
Permissions Breakdown
- search medium Allows reading/modifying search queries; combined with newtab override raises monetization risk.
- host_permissions: https://api.gameograf.com/* low Scoped to developer's own API domain; not broad.
- chrome_url_overrides: newtab medium Replaces new-tab page — prime real estate for search monetization.
Pillar Scores
Permissions4.00
Reputation6.50
Network2.00
Webstore9.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-15 14:17
Listing SHA
1f9613d9cfd9…
Force block
— not fired
Score recovered
no
Elapsed
—