BMW M5 F90 Live Wallpaper New Tab
olibnnibepelicobojjmmhmnidfbammm
Risk Score
3.58
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- NewTab override replaces every new tab page, enabling persistent search/ad monetization.
- Uninstall and install URL hijacking sends tracking events to developer domain on both events.
- Two innerHTML DOM-XSS sinks without CSP; no content_security_policy declared (MV3 default only).
- search permission paired with newtab override allows query interception for monetization.
- Developer name blank; verified publisher status partially mitigates identity opacity.
Evidence
- newtab_override manifest chrome_url_overrides.newtab set to newtab.html; replaces every new tab for all users.
- uninstall_url_hijack crx setUninstallURL → https://gameograf.com/?utm_source=gameograf&utm_medium=link&utm_campaign=bg&utm_content=uninstall
- install_url_hijack crx onInstalled opens https://gameograf.com/?utm_source=install&utm_medium=link&utm_campaign=bg&utm_content=install
- dom_xss_sink crx innerHTML sinks in popup.js and calendar.js; csp_present=false amplifies XSS risk.
- no_csp manifest content_security_policy is null; MV3 default applies but no explicit hardening.
- verified_publisher store Verified publisher badge present; domain resolves, not throwaway; partially mitigates reputation risk.
- privacy_policy api Policy fetched; scope_extension=true, data_collection=true, retention=true, third_party_sharing=true. Adequate.
- no_developer_name store developer_name is empty string; identity relies solely on email and verified publisher badge.
Permissions Breakdown
- search medium Allows reading and modifying search queries; paired with NewTab override raises monetization concern.
- chrome_url_overrides.newtab medium Replaces every new-tab page; primary surface for NewTab monetization shells.
- host_permissions: https://api.gameograf.com/* low Scoped to developer-owned API domain only; limited blast radius.
Pillar Scores
Permissions3.50
Reputation4.00
Network2.00
Webstore6.00
Maintenance3.50
Privacy0.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 15:14
Listing SHA
d4e42c8c31e7…
Force block
— not fired
Score recovered
no
Elapsed
—