Zoro Ashura Live Wallpaper
mlncbggenfclclopmhgfiobpmeehanng
Risk Score
3.39
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- NewTab override replaces every new-tab page — high-reach monetization surface with install/uninstall URL hijack confirmed.
- Uninstall and install URL hijacks redirect to gameograf.com with UTM tracking on every install/removal.
- Two innerHTML DOM-XSS sinks with no CSP (MV3 default CSP applies but extension page has null CSP) increases XSS risk.
- No developer name listed; low install count (55) limits reach but raises tail-attack concern.
- Privacy policy admits third-party data sharing; adequate but extension contacts 12 external JS hosts including Google services.
Evidence
- newtab_override manifest chrome_url_overrides.newtab present — every new-tab is replaced by extension page.
- uninstall_url_hijack crx chrome.runtime.setUninstallURL to https://gameograf.com/?utm_source=extension&utm_medium=install
- install_url_hijack crx onInstalled opens https://gameograf.com/?utm_source=extension&utm_medium=install
- dom_xss_sink crx dom_sink_innerhtml_userctrl in js/popup.js and js/calendar.js; no extension CSP declared.
- no_developer_name store developer_name is empty string; accountability reduced.
- verified_publisher store Verified publisher badge present for support@gameograf.com / gameograf.com.
- privacy_policy_classification api Policy fetched; scope_extension=true, data_collection=true, retention=true, third_party_sharing=true.
- js_external_hosts crx 12 external JS hosts including api.gameograf.com and multiple Google service domains.
Permissions Breakdown
- search medium Allows querying the browser's search engine; relevant for NewTab but grants query visibility.
- host_permissions:https://api.gameograf.com/* low Scoped to developer's own API domain; low blast radius.
- chrome_url_overrides.newtab medium Replaces new-tab page; high-reach surface for monetization and data capture.
Pillar Scores
Permissions3.00
Reputation4.50
Network2.00
Webstore7.00
Maintenance0.00
Privacy0.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 09:32
Listing SHA
28d1762d3042…
Force block
— not fired
Score recovered
no
Elapsed
—