McLaren W1 Wallpapers New Tab
ljekjledibfmiklmendbpmophiphhkmm
Risk Score
3.42
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- NewTab override replaces every new tab with developer-controlled content; persistent high-reach surface.
- Uninstall and install URL hijacks redirect users to developer tracking URLs on lifecycle events.
- innerHTML sink in popup.js is a DOM-XSS vector if content from api.gameograf.com is unsanitized.
- Extension is 16 months stale with no CSP, leaving DOM-XSS sink unmitigated.
- mlionltd.github.io as external JS host is a third-party GitHub Pages domain outside developer control.
Evidence
- newtab_override manifest chrome_url_overrides.newtab replaces every new tab page with index.html.
- uninstall_url_hijack crx setUninstallURL targets https://gameograf.com with UTM tracking params.
- install_url_hijack crx onInstalled opens https://gameograf.com with UTM tracking params.
- dom_xss_sink crx js/popup.js assigns innerHTML from variable; no CSP to mitigate XSS.
- external_js_host_third_party crx mlionltd.github.io is an external JS host not under developer domain control.
- no_csp manifest content_security_policy is null; MV3 default applies but DOM sink is unmitigated.
- stale_extension store 16 months since last update; triple-stale fingerprint (>12mo, MV3, no CVEs).
- verified_publisher store Developer is verified publisher; resolves domain gameograf.com; reduces reputation risk.
Permissions Breakdown
- search medium Allows querying browser search API; medium risk for a NewTab override extension.
- host_permission: https://api.gameograf.com/* low Scoped to developer's own API domain only.
- chrome_url_overrides.newtab medium Replaces every new tab page; persistent high-reach surface for monetization or phishing.
Pillar Scores
Permissions3.00
Reputation3.50
Network2.50
Webstore6.50
Maintenance6.00
Privacy1.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 14:48
Listing SHA
18d59e8e0d53…
Force block
— not fired
Score recovered
no
Elapsed
—