Fire Fireplace Burning Live Wallpaper
aonhacgjmogphocecdbhkbmgbcpfdmlb
Risk Score
6.05
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Uninstall and install URL hijacks redirect to haberikra.com — classic monetization shell fingerprint.
- Privacy policy is generic Google account policy, completely unscoped to this extension; admits data collection and 3rd-party sharing.
- NewTab override combined with 'search' permission enables persistent search/ad monetization on every new tab.
- 16 dev-email siblings under info@gameograf.com indicate a factory pattern of similar monetization extensions.
- No developer name disclosed; newtab shell with external JS reaching 9 distinct domains including ad-adjacent haberikra.com.
Evidence
- install_url_hijack manifest onInstalled opens haberikra.com with UTM tracking params — confirmed monetization redirect.
- uninstall_url_hijack manifest setUninstallURL points to haberikra.com — Webstore +3.0 penalty applied.
- newtab_override manifest chrome_url_overrides.newtab replaces every new tab page; monetization surface.
- privacy_policy_generic store Policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
- operator_cluster_dev_email api info@gameograf.com has 16 sibling extensions by dev_email dimension — factory pattern.
- js_external_hosts crx 9 external JS hosts including haberikra.com, chatgpt.com, instagram.com, netflix.com, x.com — broad reach.
- maintenance_stale store 16 months since last update — falls in 12-24mo band (+6.0).
- no_developer_name store developer_name is empty string; reduces accountability.
Permissions Breakdown
- search medium Allows querying/overriding search functionality; medium risk on its own but paired with newtab override raises concern.
- chrome_url_overrides.newtab high Replaces every new tab; prime monetization surface used to inject ads/redirect searches.
Pillar Scores
Permissions5.00
Reputation5.00
Network3.50
Webstore8.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Operator Siblings (1)
Other extensions sharing this developer's compound fingerprint:
Bookkeeping
Rubric v3.6
Scored at 2026-09-16 03:21
Listing SHA
cb5a200e47f2…
Force block
— not fired
Score recovered
no
Elapsed
—