Pepe Meditation Live Wallpaper
alemhdbjiappgdahkagnbgpmpagglbdi
Risk Score
6.20
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Uninstall AND install URL both hijack to gameograf.com — confirmed monetization shell pattern.
- NewTab override redirects all new tabs to developer-controlled page with 6 hardcoded external JS hosts.
- Privacy policy is Google's generic account policy — scoped to Google, not this extension; admits data collection and 3rd-party sharing.
- Free-webmail dev (gmail) with no business website, no verified publisher badge.
- New-tab override with monetization shape: search + newtab override combo targeting major social/media platforms.
Evidence
- uninstall_url_hijack crx chrome.runtime.setUninstallURL → gameograf.com with UTM params; +3.0 Webstore.
- install_url_hijack crx onInstalled opens gameograf.com with UTM params; +2.0 Webstore.
- newtab_override manifest chrome_url_overrides.newtab = index.html; +2.0 Webstore + medium/high permission scored.
- privacy_policy_generic store Policy is Google account policy: fetched=true, scope_extension=false, data_collection=true, 3rd_party=true → +10.0 Privacy (v3.5 D).
- free_webmail_dev store sinanalkan2737@gmail.com, no business website, no verified publisher → Reputation floor 7.5.
- js_external_hosts crx 6 external hosts: gameograf.com, google.com, instagram.com, netflix.com, youtube.com, x.com. >3 distinct domains +1.5 Network.
- no_csp manifest csp_present=false on MV3 extension; +2.0 Network (MV2 rule does not apply, MV3 default strict).
- search_permission_newtab_combo manifest search permission + newtab override = search/newtab monetization pattern; +2.0 Webstore.
Permissions Breakdown
- search medium Allows reading/manipulating search queries; paired with NewTab override amplifies search hijack risk.
- chrome_url_overrides.newtab high Replaces every new tab with extension page; core monetization surface for traffic redirect.
Pillar Scores
Permissions4.00
Reputation7.50
Network4.00
Webstore10.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 09:28
Listing SHA
231c1e4162ae…
Force block
— not fired
Score recovered
no
Elapsed
—