Vernazza Sunset Live Wallpaper
ppanejlcpfohgdmmadkhklhjajikpbof
Risk Score
3.52
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- NewTab override with uninstall+install URL hijack to gameograf.com — monetization shell pattern.
- Both onInstalled and onUninstalled redirect to developer domain with UTM tracking params.
- Two innerHTML DOM-XSS sinks (popup.js, calendar.js) with no CSP to mitigate.
- No developer name listed; verified publisher status provides limited accountability for a wallpaper/NewTab hybrid.
- 12 external JS hosts including Google services used without content_scripts — broad reach for a simple wallpaper.
Evidence
- newtab_override manifest chrome_url_overrides.newtab set to newtab.html — replaces every new tab for all users.
- uninstall_url_hijack crx setUninstallURL → https://gameograf.com/?utm_source=extension&utm_medium=install
- install_url_hijack crx onInstalled opens https://gameograf.com/?utm_source=extension&utm_medium=install
- dom_xss_sinks crx innerHTML assigned from variable in popup.js and calendar.js; csp_present=false amplifies risk.
- no_csp manifest content_security_policy is null; MV3 default applies but no explicit hardening declared.
- verified_publisher store Publisher verified; domain gameograf.com resolves, looks_throwaway=false.
- privacy_policy api Policy fetched, scoped, discloses data collection, retention, third-party sharing — fully adequate.
- low_installs store Only 21 installs; no rating. Limited blast radius but monetization patterns still present.
Permissions Breakdown
- search medium Can interact with browser search functionality; paired with newtab override raises monetization concern.
- host_permissions: https://api.gameograf.com/* low Scoped to developer-controlled domain only; acceptable for wallpaper data fetch.
- chrome_url_overrides.newtab medium Replaces new-tab page — high-reach surface, monetization vector, scored per v2 calibration (a).
Pillar Scores
Permissions3.50
Reputation4.00
Network2.00
Webstore7.50
Maintenance1.50
Privacy0.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 11:42
Listing SHA
90636ae4f844…
Force block
— not fired
Score recovered
no
Elapsed
—