Eternal Abyss Gan Xuan Live Wallpaper
kddmpiegkhognnbickdokphhclpnpiad
Risk Score
6.23
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Google's own privacy policy used as extension policy — admits data collection/3rd-party sharing with no extension scope.
- NewTab override with search permission creates search-hijacking and monetization surface.
- Uninstall and install URL hijacks redirect to gameograf.com — confirmed monetization shell pattern.
- No developer name listed; missing 'Offered by' identity for a newtab extension.
- innerHTML DOM-XSS sinks in popup.js and calendar.js with no CSP to mitigate.
Evidence
- newtab_override manifest chrome_url_overrides.newtab set to newtab.html; combined with 'search' permission = search hijack capability.
- privacy_policy_generic_google store Privacy policy URL is myaccount.google.com/privacypolicy — Google's own policy, not scoped to this extension.
- install_uninstall_url_hijack crx Both onInstalled and uninstall URLs redirect to gameograf.com with UTM tracking — monetization shell pattern.
- no_csp manifest content_security_policy is null; DOM-XSS sinks in popup.js and calendar.js have no mitigation.
- dom_xss_sinks crx dom_sink_innerhtml_userctrl in js/popup.js and js/calendar.js; no CSP present elevates risk.
- no_developer_name store developer_name is empty string; 'Offered by' identity missing for a newtab override extension.
- privacy_policy_admits_third_party_sharing api Classification: scope_extension=false, data_collection=true, third_party_sharing=true → worst-case privacy score.
- verified_publisher store verified_publisher=true but no monetization discount applies; install/uninstall hijack present (v3.5 E).
Permissions Breakdown
- search medium Allows querying browser search provider; paired with newtab override this enables search hijacking.
- host_permissions: https://api.gameograf.com/* low Scoped to developer's own API domain; limited blast radius.
- chrome_url_overrides.newtab high Replaces new-tab page; high-visibility monetization surface, search override risk.
Pillar Scores
Permissions4.00
Reputation4.50
Network3.50
Webstore8.00
Maintenance1.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 07:57
Listing SHA
b9a7085f682d…
Force block
— not fired
Score recovered
no
Elapsed
—