This Duck Live Wallpaper
lcoeefcacppckhidgmkdlnbeajkmeick
Risk Score
6.38
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- NewTab override with search permission: classic search-monetization shell; 8 sibling extensions from same operator cluster.
- Privacy policy URL unreachable (fetch_error): effective no-policy, score treated as 10.0.
- Uninstall and install URL hijack both active — tracks user lifecycle for marketing.
- Operator cluster of 32 extensions under same dev email; compound fingerprint matches 8 siblings — mass-deployment pattern.
- Two innerHTML DOM-XSS sinks with no CSP present — elevated XSS risk on newtab page.
Evidence
- newtab_override manifest chrome_url_overrides.newtab set to newtab.html; search permission declared — search monetization pattern.
- operator_cluster api sibling_count=8 compound; 32 extensions share dev_email support@gameograf.com.
- uninstall_url_hijack crx setUninstallURL → https://gameograf.com/?utm_source=extension&utm_medium=install (3rd-party redirect).
- install_url_hijack crx onInstalled opens https://gameograf.com/?utm_source=extension&utm_medium=install.
- privacy_policy_unreachable api fetch_error:ConnectionError on https://api.gameograf.com/gameograf-privacy-policy.html — treated as no policy.
- dom_xss_sinks_no_csp crx 2x dom_sink_innerhtml_userctrl in popup.js and calendar.js; csp_present=false amplifies risk.
- no_csp_mv3 manifest content_security_policy is null; MV3 has strict default but explicit null means no extension-page CSP declared.
- new_tab_search_engine_count api search_engine_count=1 (google.com only); no multi-search aggregator but newtab+search combo confirmed.
Permissions Breakdown
- search medium Allows reading search queries; paired with newtab override enables search monetization.
- host_permissions: https://api.gameograf.com/* low Scoped to dev-controlled API domain; used for wallpaper assets.
- chrome_url_overrides.newtab high Replaces every new tab — high-reach monetization surface; search override companion.
Pillar Scores
Permissions4.00
Reputation5.50
Network2.00
Webstore9.00
Maintenance1.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Operator Siblings (15)
Other extensions sharing this developer's compound fingerprint:
- fdjpcjggpgdmdikmhoagohakklihimbo
- ammndifopdgpjcpmpbdenfcafipnejlj
- ojhigfemmjpjnmhidflhdlcahgdiiija
- ieocbmlfbinpcffofcjmpbjokkfghodc
- faaegcmakhlmoheamicddkfcmmjoljnd
- amfeinhgbpnnjihjiomibeodnainnjkd
- ceoamfmlgefiljnligpdkdindckojbim
- hlacaekdajdgiiofjplpofbgebgjbnco
- kngkldhmcncemclgjgbbogplfeoppkll
- gfcbimjpmoeofbmnjedjfkemdinagkmp
- kmjgnidfglamdnllpoidpfikcodjapih
- heakmhbelclpalglpiceoocofnkcjefb
- gbeldgdcloiceglhpdnkhbafeoddjehm
- epjpkhahnajkdjjfkeadcgfmfjfgdohf
- fjmlhfejlohohljeioedcliggbfkihdf
Bookkeeping
Rubric v3.6
Scored at 2026-09-16 04:37
Listing SHA
d55baeee5ea3…
Force block
— not fired
Score recovered
no
Elapsed
—