Lamine Yamal Wallpapers Gameograf
pognhgjjeijdaemaidolkajdckdoofih
Risk Score
5.53
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic policy (fetch failed, not extension-scoped); no data handling disclosure.
- NewTab override with uninstall/install URL hijack to gameograf.com — classic monetization shell pattern.
- External JS host mlionltd.github.io is unrecognized third-party GitHub Pages domain outside dev control.
- No developer name listed; verified publisher but privacy policy is a third-party URL that couldn't be fetched.
- Maintenance at 16 months stale; verified-publisher discount capped at -1.0 per invariant 0c (stale >18mo nearly reached, monetization context).
Evidence
- newtab_override manifest chrome_url_overrides.newtab = index.html; search permission declared — NewTab monetization pattern.
- uninstall_url_hijack crx setUninstallURL targets https://gameograf.com/?utm_source=uninstall — third-party UTM tracking.
- install_url_hijack crx onInstalled opens https://gameograf.com/?utm_source=install — UTM monetization on install.
- privacy_policy_fetch_failed api Privacy policy URL is Google's generic policy; fetch returned SSLError — not extension-scoped.
- external_host_unrecognized crx js_external_hosts includes mlionltd.github.io — uncontrolled third-party GitHub Pages domain.
- no_developer_name store developer_name is empty string; verified publisher but no display name raises accountability gap.
- verified_publisher store verified_publisher=true provides some accountability; domain gameograf.com resolves, age 2050 days.
- csp_absent_mv3 manifest content_security_policy is null; MV3 has strict default but no explicit CSP declared.
Permissions Breakdown
- search medium Allows search provider manipulation; paired with newtab override amplifies monetization risk.
- host_permission: https://api.gameograf.com/* low Scoped to dev-owned domain only; limited blast radius.
- chrome_url_overrides.newtab medium Replaces new-tab page; classic monetization surface for ad injection and search hijacking.
Pillar Scores
Permissions4.00
Reputation4.50
Network2.50
Webstore7.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-16 00:29
Listing SHA
ad745ab61511…
Force block
— not fired
Score recovered
no
Elapsed
—