Snoopy Christmas Wallpaper
chdmpgffefghffnplbahpklleiclneea
Risk Score
3.92
Risk Level:
Low
Recommendation:
🚫 BLOCK
Top Risks
- New-tab override by Gmail dev with uninstall/install URL hijack to owhit.com — classic monetization shell.
- Privacy policy is Google's own policy (not scoped to this extension) — admits data collection + 3rd-party sharing: +10.0 privacy.
- Free-webmail dev (gmail), no developer name, no business domain — unverifiable identity.
- Install and uninstall URL hijack to third-party domain owhit.com enables tracking of user lifecycle.
- JS contacts 8 external hosts (YouTube, Netflix, Instagram, X, ChatGPT, etc.) with no CSP — broad unexplained reach.
Evidence
- newtab_override manifest chrome_url_overrides.newtab = index.html; replaces every new tab with developer page.
- uninstall_url_hijack crx setUninstallURL → https://owhit.com/uninstall; 3rd-party tracking on removal.
- install_url_hijack crx onInstalled opens https://owhit.com/snoopy-christmas-wallpaper; 3rd-party tracking on install.
- generic_privacy_policy store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- free_webmail_no_devname store Developer email tekbatuhan64@gmail.com; developer_name empty; no business domain.
- external_hosts_broad crx JS contacts chatgpt.com, instagram.com, netflix.com, x.com, youtube.com, owhit.com — 8 hosts, no CSP.
- no_csp manifest content_security_policy is null; MV3 strict defaults apply but no explicit CSP declared.
- verified_publisher_claimed store verified_publisher=true but dev email is free webmail with no resolvable business domain — cap at -1.0 per 0c.
Permissions Breakdown
- search medium Allows reading/modifying search provider behavior; combined with newtab override this enables search hijacking.
- chrome_url_overrides.newtab high Replaces every new tab with developer-controlled page; primary monetization/surveillance surface.
Pillar Scores
Permissions5.00
Reputation7.50
Network2.00
Webstore9.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 04:06
Listing SHA
a5785c661ea3…
Force block
— not fired
Score recovered
no
Elapsed
—