Anime Cats Wallpaper
kfgnclocjgenagihhalijajmkckigpak
Risk Score
5.57
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy URL returns fetch error — effective no-policy; NewTab extension cannot be audited for data practices.
- NewTab override with install/uninstall URL hijacks signals monetization-shell pattern.
- Uninstall URL hijack redirects to gameograf.com with UTM tracking params.
- Install URL hijack opens gameograf.com on install — ad-funnel behavior.
- No CSP present (MV3) and innerHTML sink in popup.js raises DOM-XSS risk.
Evidence
- privacy_policy_fetch_error api Privacy policy URL https://gameograf.com/privacy-policy/ returned HTTPError; treated as no policy.
- uninstall_url_hijack crx chrome.runtime.setUninstallURL points to gameograf.com with UTM campaign params.
- install_url_hijack crx onInstalled opens gameograf.com with UTM install tracking — monetization funnel.
- newtab_override manifest chrome_url_overrides.newtab = index.html; NewTab replaced for all sessions.
- no_csp manifest content_security_policy is null; MV3 default applies but no explicit hardening.
- dom_xss_sink crx js/popup.js: innerHTML assigned from variable without sanitization — DOM-XSS risk.
- no_developer_name store developer_name field is empty in listing.
- verified_publisher store Verified publisher badge present; domain gameograf.com resolves, age 2051 days.
Permissions Breakdown
- search medium Allows reading/overriding search engine; medium risk for a NewTab extension.
- host_permissions: https://api.gameograf.com/* low Scoped to developer's own API domain only.
- chrome_url_overrides.newtab medium Replaces new-tab page; primary monetization surface for this category.
Pillar Scores
Permissions4.00
Reputation4.50
Network2.00
Webstore7.50
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-16 04:52
Listing SHA
08af1e501796…
Force block
— not fired
Score recovered
no
Elapsed
—