Kimetsu no Yaiba Live Wallpaper Chrome OS Theme
kodaloakchjhcakljbgmmldaieipmhbm
Risk Score
3.52
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- NewTab override with uninstall+install URL hijack to gameograf.com — monetization shell pattern.
- Both uninstall and install URL hijack to 3rd-party domain (+3.0+2.0 webstore signals).
- New-tab override with search permission: classic ad-monetization newtab shape.
- Two DOM-XSS innerHTML sinks with no CSP; escalated to +2.0 each under FIX B.
- No developer name listed; verified publisher but thin identity signal for 15-install theme.
Evidence
- uninstall_url_hijack manifest setUninstallURL → https://gameograf.com/?utm_source=extension&utm_medium=install (+3.0 webstore)
- install_url_hijack manifest onInstalled opens https://gameograf.com/?utm_source=extension&utm_medium=install (+2.0 webstore)
- chrome_url_overrides.newtab manifest newtab.html override declared; +2.0 webstore newtab-monetization shape.
- csp_absent_mv3 crx content_security_policy is null; MV3 default applies but no CSP amplifies innerHTML risk.
- dom_sink_innerhtml crx Two innerHTML sinks (popup.js, calendar.js) with csp_present==false → +2.0 each per FIX B.
- verified_publisher store gameograf.com resolves, not throwaway; verified publisher discount applied (-3.0 reputation).
- privacy_policy_full api Policy fetched, scoped, data_collection+retention+third_party_sharing all true → Privacy=0.0.
- no_developer_name store developer_name empty string; +1.0 reputation penalty applied.
Permissions Breakdown
- search medium Allows reading user's search queries; paired with newtab override amplifies monetization potential.
- host_permissions: https://api.gameograf.com/* low Scoped to dev's own domain; limits exfil surface but enables data transmission to dev.
- chrome_url_overrides.newtab medium Replaces every new tab; high reach, typical monetization vector for theme/wallpaper shells.
Pillar Scores
Permissions3.50
Reputation3.50
Network2.00
Webstore7.00
Maintenance0.00
Privacy0.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 10:52
Listing SHA
2422b7a20030…
Force block
— not fired
Score recovered
no
Elapsed
—