Messi Live Wallpaper
acekegimgonaofondhejifbnpahnlbek
Risk Score
6.22
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Uninstall & install URL hijack both redirect to gameograf.com — clear monetization shell pattern.
- Privacy policy is Google's generic policy, not scoped to this extension; admits data collection and 3rd-party sharing → +10 privacy.
- NewTab override combined with 'search' permission channels all new-tab traffic through developer-controlled page.
- Free-webmail developer (gmail), no developer name, no verifiable business identity.
- No CSP on MV3; external JS hosts include social/media platforms (instagram, netflix, youtube, x.com) suggesting data harvesting surface.
Evidence
- uninstall_url_hijack manifest chrome.runtime.setUninstallURL → gameograf.com with UTM params; classic monetization redirect.
- install_url_hijack manifest onInstalled opens gameograf.com with UTM params; traffic monetization on install.
- newtab_override manifest chrome_url_overrides.newtab = index.html; every new tab routed through extension.
- privacy_policy_generic store Policy URL is Google's own account policy (scope_extension=false, data_collection=true, third_party_sharing=true).
- free_webmail_no_dev_name store Developer email halilseker3455@gmail.com; no developer_name; no verifiable business domain.
- external_js_hosts crx JS contacts gameograf.com, instagram.com, netflix.com, youtube.com, x.com — broad social/media surface.
- no_csp manifest content_security_policy is null; MV3 default applies but no explicit restriction declared.
- verified_publisher_with_monetization store Verified publisher badge present but v3.5(E) cap applies: monetization redirect detected → discount capped at -1.0.
Permissions Breakdown
- search medium Allows reading/manipulating search queries; medium risk in newtab monetization context.
- chrome_url_overrides.newtab high Replaces every new tab; core mechanism for traffic monetization shells.
Pillar Scores
Permissions4.00
Reputation7.50
Network4.00
Webstore10.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 12:36
Listing SHA
583fda455c01…
Force block
— not fired
Score recovered
no
Elapsed
—