Minecraft Cherry Blossom Garden Live Wallpaper
baidmllhegbpbcijkadajlpobgdbenfp
Risk Score
6.26
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Uninstall and install URL both hijacked to gameograf.com — confirmed monetization shell pattern.
- Minecraft brand impersonation by unverified gmail developer with no confirmed ownership.
- New-tab override + search permission enables search/traffic hijacking for ad monetization.
- Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and 3rd-party sharing.
- JS contacts gameograf.com plus major platforms (Netflix, YouTube, Instagram, X) — broad external reach for a wallpaper.
Evidence
- uninstall_url_hijack manifest setUninstallURL targets gameograf.com with UTM params — confirmed 3rd-party monetization redirect.
- install_url_hijack manifest onInstalled opens gameograf.com — double hijack fingerprint matches game-portal/monetization shell.
- brand_impersonation store Title claims Minecraft brand; developer is unverified gmail account with no confirmed Mojang/Microsoft affiliation.
- newtab_override manifest chrome_url_overrides.newtab replaces new tab with index.html — primary surface for search/ad monetization.
- privacy_policy_generic store Policy URL is Google account policy: scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0.
- js_external_hosts crx gameograf.com + 5 major platforms in JS host list; wallpaper has no stated need to contact Netflix or Instagram.
- free_webmail_developer store Developer email oktaybahcivan27@gmail.com — free webmail, no verified business, no website.
- search_permission_plus_newtab manifest search permission combined with newtab override is canonical search-hijack pattern per rubric.
Permissions Breakdown
- search medium Allows manipulation of search provider; combined with newtab override enables search hijacking.
- chrome_url_overrides.newtab high Replaces new tab page — primary monetization vector for traffic/search hijacking shells.
Pillar Scores
Permissions5.00
Reputation8.50
Network2.00
Webstore10.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-15 21:39
Listing SHA
05ee6ec93454…
Force block
— not fired
Score recovered
no
Elapsed
—