Assassin’s Creed Valhalla Eivor Live Wallpaper
apmohjaadengjgicdakjnfbacflofpkd
Risk Score
6.13
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Uninstall and install URL both hijack to gameograf.com with UTM tracking — confirmed monetization shell.
- Privacy policy is Google's own policy (scope_extension=false, data_collection=true, third_party_sharing=true) — worst-case generic policy, scores +10.
- NewTab override + search permission is a textbook ad-revenue / search-hijack pattern.
- Free-webmail developer (gmail.com), no verified publisher, no business domain — unaccountable.
- Extension contacts gameograf.com plus major social/media domains (Instagram, Netflix, YouTube, X) from a wallpaper app.
Evidence
- install_url_hijack crx onInstalled opens gameograf.com with UTM params — confirmed monetization redirect.
- uninstall_url_hijack crx setUninstallURL points to gameograf.com with UTM params — +3.0 webstore.
- newtab_override manifest chrome_url_overrides.newtab = index.html; combined with search permission = search monetization shape.
- privacy_policy_generic store Policy is Google account policy: scope_extension=false, data_collection=true, third_party_sharing=true → +10 privacy.
- free_webmail_dev store Developer email aliolga956@gmail.com, no business domain, no verified publisher → reputation floor 7.5.
- external_hosts_mismatch crx JS contacts gameograf.com, instagram.com, netflix.com, youtube.com, x.com — unrelated to wallpaper function.
- no_csp manifest content_security_policy is null; MV3 default applies but no explicit CSP declared.
- low_installs store Only 40 installs; combined with newtab+search override signals early-stage monetization shell.
Permissions Breakdown
- search medium Allows querying browser search functionality; combined with newtab override raises monetization risk.
- chrome_url_overrides.newtab high Replaces new tab with extension page; classic search/ad monetization vector.
Pillar Scores
Permissions3.00
Reputation7.50
Network2.00
Webstore10.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 08:28
Listing SHA
8dee9e85f3f7…
Force block
— not fired
Score recovered
no
Elapsed
—