Portugal National Team – FIFA World Cup 2026 Squad Top 20 Wallpapers
moniepcmaabbodpinonaakcpjfcjajhi
Risk Score
5.62
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- NewTab override combined with uninstall-URL hijack to gameograf.com reveals monetization-shell pattern.
- Privacy policy is Google's own generic policy — not scoped to this extension; admits data collection and third-party sharing.
- Three medium-severity jQuery CVEs (1.9.1) bundled with no CSP — XSS amplifier active.
- Free-webmail developer (eminearsiz0@gmail.com) with no verified publisher status and no business domain.
- 12 external JS hosts including social/ad-adjacent domains; no CSP on MV3 provides no script-src enforcement.
Evidence
- uninstall_url_hijack manifest chrome.runtime.setUninstallURL → https://gameograf.com/?utm_source=ovkas — 3rd-party monetization redirect on uninstall.
- newtab_override manifest chrome_url_overrides.newtab = index.html; every new tab hijacked, search perm present.
- generic_privacy_policy store Policy URL is myaccount.google.com/privacypolicy — Google's policy, not extension-scoped; data_collection+third_party_sharing=true.
- jquery_cves crx jquery@1.9.1 carries 3 medium XSS CVEs (CVE-2015-9251, CVE-2019-11358, CVE-2020-11023); fixed_in 3.5.0.
- no_csp manifest content_security_policy is null on MV3; no script-src enforcement despite 12 external hosts and CVE-bearing jQuery.
- free_webmail_dev store Developer email eminearsiz0@gmail.com — free webmail, no verified publisher, no business website.
- install_url_hijack manifest onInstalled opens index.html — internal redirect; lower risk but confirms shell pattern.
- external_hosts_breadth crx 12 external JS hosts: gameograf.com, crazycraftz.com, jqueryui.com, popper.js.org among others.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@1.9.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11023 | jquery@1.9.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@1.9.1 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- search medium Allows reading/overriding search queries; elevated in a NewTab shell.
- topSites medium Exposes user's most-visited sites; privacy-sensitive in an ad-monetization context.
- unlimitedStorage low Allows unlimited local storage; low standalone risk.
- storage low Standard key-value storage; low risk.
- chrome_url_overrides.newtab high Replaces every new tab with extension page; high-reach monetization surface.
Pillar Scores
Permissions4.30
Reputation7.50
Network4.00
Webstore9.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure3.75
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 08:27
Listing SHA
6ba071e43453…
Force block
— not fired
Score recovered
no
Elapsed
—