Hello Kitty Live Wallpaper
eanhhbidjoehpfkifoggcndlcokajecd
Risk Score
5.59
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- Uninstall AND install URL both hijacked to gameograf.com affiliate/ad tracker — confirmed traffic-monetization shell.
- Privacy policy is generic Google account policy; not scoped to this extension, admits data collection and 3rd-party sharing.
- NewTab override with search permission; external JS hosts include Instagram, Netflix, YouTube, X — broad surveillance surface.
- Free-webmail developer (haliliseker44@gmail.com), no verified publisher, no business domain — unaccountable operator.
- No CSP on MV3 extension with external JS hosts contacting 6 distinct registrable domains.
Evidence
- install_url_hijack crx onInstalled opens https://gameograf.com/?utm_source=ovkas — affiliate monetization redirect.
- uninstall_url_hijack crx setUninstallURL targets https://gameograf.com/?utm_source=ovkas — 3rd-party hijack confirmed.
- newtab_override manifest chrome_url_overrides.newtab = index.html; every new tab is replaced by this extension.
- privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- free_webmail_developer store Developer email haliliseker44@gmail.com; no business domain; unverified publisher.
- external_js_hosts crx JS contacts gameograf.com, instagram.com, netflix.com, youtube.com, x.com, google.com — 6 domains.
- no_csp manifest content_security_policy is null; csp_present=false despite external host contacts.
- new_tab_monetization_pattern store NewTab + search override + install/uninstall hijack to ad-tracker = classic monetization shell pattern.
Permissions Breakdown
- search medium Allows search provider manipulation; pairs with newtab override for traffic monetization.
- chrome_url_overrides.newtab high Replaces every new tab; core mechanism for ad/search-monetization shells.
Pillar Scores
Permissions3.00
Reputation7.50
Network2.00
Webstore10.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 12:46
Listing SHA
9dd03b97a1a6…
Force block
— not fired
Score recovered
no
Elapsed
—