BLACKPINK Wallpapers New Tab Lisa Rose Jennie Jisoo
nmknbcamoginleehgkmlilgnkhkphgdh
Risk Score
5.73
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Google's own privacy policy used — not scoped to this extension, admits data collection and 3rd-party sharing (+10 privacy).
- Uninstall and install URL hijacks redirect users to gameograf.com tracking links (+3+2 webstore).
- bit.ly affiliate/cloaking link in JS hosts — redirects destination opaque (+1.5 webstore).
- NewTab override controls every new tab session; combined with 'search' permission enables search monetization.
- months_since_update=16 (12-24mo band) and no CSP — DOM-XSS sink in popup.js unmitigated.
Evidence
- uninstall_url_hijack crx chrome.runtime.setUninstallURL to gameograf.com with UTM tracking params — monetization redirect.
- install_url_hijack crx onInstalled opens gameograf.com with UTM tracking — install hijack confirmed.
- privacy_policy_google_generic store Privacy URL is myaccount.google.com/privacypolicy — Google's policy, not scoped to this extension.
- privacy_policy_classification api scope_extension=false, data_collection=true, third_party_sharing=true — D-clause: +10.0 privacy.
- affiliate_hit_bitly crx bit.ly in js_external_hosts — generic short-link redirector flagged as affiliate/cloaking.
- newtab_override_search_perm manifest chrome_url_overrides.newtab + search permission — classic search-monetization NewTab shell.
- dom_sink_innerhtml crx popup.js assigns innerHTML from variable with no CSP — DOM-XSS risk unmitigated.
- no_developer_name store developer_name is empty string — no 'Offered by' identity presented to users.
Permissions Breakdown
- search medium Allows search-provider interaction; paired with newtab override amplifies monetization risk.
- host_permissions: https://api.gameograf.com/* low Scoped to developer's own API domain; low breadth but enables data exfil to dev server.
- chrome_url_overrides.newtab medium Replaces every new tab with extension page; high user-reach monetization surface.
Pillar Scores
Permissions3.50
Reputation5.50
Network2.00
Webstore8.50
Maintenance6.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 12:46
Listing SHA
2d9f608bc0bc…
Force block
— not fired
Score recovered
no
Elapsed
—