Power Chainsaw Man Live Wallpaper
kenndofkbpgkfhaecjmnjmehhhbnioeh
Risk Score
5.68
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy hosted on unrelated domain (haberikra.com), admits data collection + third-party sharing, not scoped to this extension → Privacy pillar 10.0
- NewTab override + search permission + uninstall/install URL hijack to gameograf.com = classic monetization shell pattern
- Operator cluster: 5 sibling extensions share same dev email/install/uninstall URL fingerprint
- Stale 15 months with NewTab override and newtab monetization shape; capability-gate applies to verified-publisher discount
- innerHTML DOM-XSS sink in popup.js with no CSP present on MV3 extension
Evidence
- newtab_override manifest chrome_url_overrides.newtab set to newtab.html; every new tab replaced.
- uninstall_url_hijack crx setUninstallURL → https://gameograf.com/?utm_source=gameograf&utm_campaign=bg&utm_content=uninstall
- install_url_hijack crx onInstalled opens https://gameograf.com/?utm_source=install&utm_campaign=bg&utm_content=install
- privacy_policy_mismatch api Policy on haberikra.com (unrelated domain); scope_extension=false, data_collection=true, third_party_sharing=true.
- operator_cluster api 5 extensions share dev email; compound fingerprint matches 2 siblings with same install/uninstall URLs.
- no_csp manifest content_security_policy is null; dom_sink_innerhtml_userctrl present in popup.js.
- verified_publisher_capability_gate store Verified publisher but exercises newtab override (HIGH capability) → -1.0 cap on discount per invariant 0c/0b.
- maintenance_stale store 15 months since update; 6-12mo band = +3.5, then stale>18mo cap not triggered but >12mo triggers +6.0 bracket.
Permissions Breakdown
- search medium Allows querying browser search engine; combined with newtab override raises monetization risk.
- host_permissions: https://api.gameograf.com/* low Scoped to dev-controlled domain only; limited surface.
- chrome_url_overrides.newtab medium Replaces every new tab; primary monetization vector for this category.
Pillar Scores
Permissions4.00
Reputation4.50
Network2.00
Webstore8.50
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Operator Siblings (13)
Other extensions sharing this developer's compound fingerprint:
- ieepfmpmjnjidennkopcbamjjdemhjcf
- chjbfnbpbgjnofhahgblpcifjcbkolcp
- bpicplogeibhabicoedobpchdkngbhjh
- jmokcnonladmkkdlgbalffkjiogfcgha
- aaobffjniaghknbgjdkigmcnapghemfa
- cfbobdhebljlbkhdhnikebhhijocphfo
- ckcailiifgopnblmaeaefimdgnaelcph
- dpkgeginpcjfcgnjicpkfkkbnpailidn
- hmagnnippelpfgkmbdnepolcgjlmbohh
- jimikjehahhdekhbmhpbmbponjcimajc
- jofgjibhmlaeofgmidllemkckkpgnpbd
- iimgbphfdpnahafdmikdjnpfnffnbkcl
- gafbkkfalgndkoilabfhmjjjgeihboed
Bookkeeping
Rubric v3.6
Scored at 2026-09-15 12:39
Listing SHA
5ad54b2b12a8…
Force block
— not fired
Score recovered
no
Elapsed
—