Ariana Grande Wallpapers Gameograf
nphkeajdhjhlpeipglokhkcgaeamlifa
Risk Score
5.61
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Uninstall URL hijack to gameograf.com tracking endpoint — confirmed traffic-monetization pattern.
- Install URL hijack to gameograf.com tracking endpoint — fires on every install.
- NewTab override with search override: ad-monetization shell pattern on every new tab.
- Privacy policy is an unfetchable Google account URL — not scoped to this extension at all.
- Maintenance gap of 16 months raises abandonment/acquisition risk on NewTab surface.
Evidence
- uninstall_url_hijack manifest chrome.runtime.setUninstallURL → https://gameograf.com/?utm_source=uninstall; classic monetization/tracking redirect.
- install_url_hijack manifest onInstalled opens https://gameograf.com/?utm_source=install; 3rd-party URL on every install.
- newtab_override manifest chrome_url_overrides.newtab = index.html; controls every new tab opened by user.
- privacy_policy_fetch_failed api Policy URL is Google account page; fetched==false (SSLError); not extension-scoped. Privacy pillar = 10.0.
- dom_xss_sink crx js/popup.js: innerHTML assigned from variable without CSP — DOM-XSS risk.
- external_host_mlionltd_github_io crx JS loads from mlionltd.github.io — third-party GitHub Pages host, not developer-controlled domain.
- maintenance_gap store 16 months since last update; NewTab extension with monetization shape and no active maintenance.
- search_override_permission manifest search permission declared alongside newtab override — dual monetization surface.
Permissions Breakdown
- search medium Allows overriding search provider; monetization vector for NewTab extensions.
- chrome_url_overrides.newtab medium Replaces new-tab page; high-traffic surface for ad/affiliate monetization.
- host_permissions: https://api.gameograf.com/* low Scoped to own API domain; limited blast radius.
Pillar Scores
Permissions4.00
Reputation5.00
Network2.00
Webstore7.50
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-16 00:30
Listing SHA
572291f49eef…
Force block
— not fired
Score recovered
no
Elapsed
—