McLaren 570S Live Wallpaper New Tab
ldnffjgldajkogjcneaoefcjfgpjcjnl
Risk Score
3.33
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- NewTab override replaces browser new-tab page — primary monetization/search-hijack surface.
- Uninstall and install URL hijacks both fire to gameograf.com tracking URLs.
- No CSP declared (MV3 default applies but csp_present=false); innerHTML sink in popup.js creates DOM-XSS risk.
- Developer name empty; verified publisher status is present but extension is 15 months stale.
- Search permission combined with newtab override raises search-provider concern despite single engine seen.
Evidence
- newtab_override manifest chrome_url_overrides.newtab set to newtab.html — replaces new-tab page.
- uninstall_url_hijack crx setUninstallURL targets https://gameograf.com/?utm_source=gameograf&utm_medium=link&utm_campaign=bg&utm_content=uninstall
- install_url_hijack crx onInstalled opens https://gameograf.com/?utm_source=install&utm_medium=link&utm_campaign=bg&utm_content=install
- dom_xss_sink crx innerHTML assigned from variable in js/popup.js; no CSP to mitigate.
- verified_publisher store Developer has verified publisher badge; domain gameograf.com resolves and is not throwaway.
- stale_extension store 15 months since last update (June 2025); maintenance pillar elevated to 6.0.
- privacy_policy_adequate api Policy fetched; scope_extension=true, data_collection=true, retention=true, third_party_sharing=true — full disclosure.
- low_installs store Only 210 installs; no ratings; operator_cluster sibling_count=0.
Permissions Breakdown
- search medium Grants ability to interact with browser search; medium risk for a NewTab override context.
- host_permissions: https://api.gameograf.com/* low Scoped to dev-controlled API domain only; narrow host access.
- chrome_url_overrides.newtab medium Replaces new-tab page; monetization/search-hijack surface per v2 calibration rule (a).
Pillar Scores
Permissions3.00
Reputation3.50
Network2.00
Webstore6.00
Maintenance6.00
Privacy1.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 07:31
Listing SHA
286c1ce189c7…
Force block
— not fired
Score recovered
no
Elapsed
—