Mikasa Gothic Attack On Titan 4K Wallpaper
aingkjoclpkpbjjogalmpbpjiccacjnl
Risk Score
5.58
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Install and uninstall URL hijack both pointing to haberikra.com — classic traffic-monetization shell pattern.
- Privacy policy is Google's own policy, not scoped to this extension; admits data collection and 3rd-party sharing (+10 privacy).
- NewTab override + search permission with 9 external JS hosts including haberikra.com is a monetization aggregator fingerprint.
- No CSP declared on MV3 extension with 9 external hosts making network behavior uncontrolled.
- Stale 16 months with newtab override; maintenance risk elevated.
Evidence
- install_url_hijack manifest onInstalled opens https://haberikra.com/?utm_source=install — 3rd-party traffic redirect.
- uninstall_url_hijack manifest setUninstallURL points to https://haberikra.com/?utm_source=uninstall — monetization shell signal.
- newtab_override manifest chrome_url_overrides.newtab = newtab.html; replaces every new-tab page for all users.
- generic_privacy_policy store Privacy URL is Google's own policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- js_external_hosts crx 9 external hosts including haberikra.com, chatgpt.com, instagram.com, netflix.com, youtube.com, x.com.
- no_csp manifest content_security_policy is null; no CSP on MV3 extension with broad external JS host list.
- stale_extension store Last updated May 3 2025; 16 months since update with newtab override active.
- install_count_low store Only 340 installs; fan/theme shell pattern with wallpaper title and monetization infrastructure.
Permissions Breakdown
- search medium Allows reading/modifying search queries; paired with newtab override creates search-monetization surface.
- chrome_url_overrides.newtab medium Replaces every new-tab page; primary vector for traffic monetization and ad injection.
Pillar Scores
Permissions3.00
Reputation5.50
Network4.50
Webstore9.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 10:01
Listing SHA
b7cecb41c6a5…
Force block
— not fired
Score recovered
no
Elapsed
—