Luffy & Straw Hat Pirates Flag Live Wallpaper
bdhbbdfmkmhbeapbpeaoaffimhgppnem
Risk Score
6.14
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Uninstall and install URL hijack to owhit.com: classic monetization shell pattern sending users to 3rd-party site on every install/uninstall.
- NewTab override replaces every new tab with extension page; combined with 'search' permission enables full search-monetization takeover.
- Privacy policy is Google's own generic policy — not scoped to this extension at all; data_collection + third_party_sharing admitted without extension context.
- Free-webmail developer (cenk4790@gmail.com) with no business domain; no verified publisher; domain_age unresolvable.
- External JS hosts include owhit.com, Netflix, Instagram, YouTube, OpenAI, X — far exceeding a wallpaper extension's stated function.
Evidence
- uninstall_url_hijack crx setUninstallURL → https://owhit.com/uninstall; +3.0 Webstore per rubric.
- install_url_hijack crx onInstalled opens https://owhit.com/luffy-straw-hat-pirates-flag-live-wallpaper; +2.0 Webstore.
- newtab_override manifest chrome_url_overrides.newtab = index.html; NewTab monetization pattern; +2.0 Webstore, scored as HIGH perm.
- generic_google_privacy_policy api Policy URL is myaccount.google.com/privacypolicy; scope_extension=false, data_collection=true, 3rd_party_sharing=true → Privacy +10.0 (v3.5 D).
- free_webmail_developer store cenk4790@gmail.com; no business website; not verified publisher → Reputation floor 7.5.
- js_external_hosts_mismatch crx 8 external hosts incl. owhit.com, Netflix, Instagram, OpenAI — far beyond wallpaper scope.
- no_csp manifest content_security_policy is null; MV3 strict default applies, no additional network penalty added.
- cve_findings_empty crx jquery 3.7.1 bundled; no CVEs found in cve_findings_raw. CVE pillar = 0.
Permissions Breakdown
- search medium Allows overriding search suggestions; combined with newtab override creates full search-monetization surface.
- chrome_url_overrides.newtab high Replaces every new tab with extension page; high-reach monetization vector per rubric.
Pillar Scores
Permissions4.00
Reputation7.50
Network2.00
Webstore10.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 08:20
Listing SHA
0dbe646f6ed9…
Force block
— not fired
Score recovered
no
Elapsed
—