Honda CBR1000RR Wallpapers
mggiclknhmmfhcebdeelhbhfggpbdjep
Risk Score
5.74
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- NewTab override with uninstall URL hijack and install URL hijack — classic monetization shell pattern.
- Privacy policy is Google's generic policy; not scoped to this extension, yet admits data collection and 3rd-party sharing → Privacy pillar 10.
- No CSP (MV3 default stricter but csp_present==false) combined with innerHTML DOM-XSS sink in popup.js.
- Stale 16 months with newtab override increases long-term exposure risk.
- External JS host mlionltd.github.io (GitHub Pages, uncontrolled third party) present in js_external_hosts.
Evidence
- uninstall_url_hijack manifest setUninstallURL → https://gameograf.com/?utm_source=uninstall... — traffic monetization indicator.
- install_url_hijack manifest onInstalled opens https://gameograf.com/?utm_source=install... — monetization shell pattern.
- newtab_override manifest chrome_url_overrides.newtab = index.html; full new-tab replacement.
- generic_privacy_policy store Privacy URL is Google's own policy (myaccount.google.com/privacypolicy); scope_extension=false, data_collection=true, third_party_sharing=true.
- dom_xss_sink crx popup.js uses innerHTML with variable input; no CSP to mitigate DOM-XSS.
- external_uncontrolled_host crx mlionltd.github.io listed in js_external_hosts — GitHub Pages domain, not developer-controlled.
- maintenance_stale store 16 months since last update; newtab override persists over this period.
- no_csp manifest content_security_policy is null; csp_present=false; amplifies DOM-XSS risk.
Permissions Breakdown
- search medium Allows overriding search provider; medium risk on its own.
- host_permission: https://api.gameograf.com/* low Scoped to developer's own API domain; limited blast radius.
- chrome_url_overrides.newtab medium Replaces new-tab page; monetization surface and user-experience takeover.
Pillar Scores
Permissions5.00
Reputation5.00
Network2.00
Webstore8.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 15:14
Listing SHA
2791dc9a0bc0…
Force block
— not fired
Score recovered
no
Elapsed
—