D. Luffy Live Wallpaper
ehhblemfpifkffhgbpekenedademifoe
Risk Score
6.17
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Uninstall and install URL both hijacked to gameograf.com — classic traffic-monetization shell pattern.
- New tab override replaces browser new-tab page — primary ad-monetization surface.
- Privacy policy is generic Google account policy; admits data collection & 3rd-party sharing with no extension scope.
- Free-webmail developer, empty developer name, no business domain — unverifiable identity.
- External JS contacts affiliate-flavored gameograf.com domain with UTM tracking params.
Evidence
- uninstall_url_hijack crx chrome.runtime.setUninstallURL → https://gameograf.com/?utm_source=ovkas — 3rd-party affiliate redirect on uninstall.
- install_url_hijack crx onInstalled opens https://gameograf.com/?utm_source=ovkas — 3rd-party page opened on install.
- newtab_override manifest chrome_url_overrides.newtab = index.html; monetization shell pattern for wallpaper/NewTab category.
- privacy_policy_generic store Policy is Google account policy (scope_extension=false, data_collection=true, third_party_sharing=true) — +10.0 privacy.
- developer_identity store Developer name empty, email is free Gmail (halilseker3455@gmail.com), no business domain — elevated reputation risk.
- js_external_hosts crx gameograf.com plus google/instagram/netflix/youtube/x.com referenced in JS; gameograf carries UTM affiliate params.
- verified_publisher store Verified publisher badge present; applies -3.0 to reputation but capped at -1.0 due to monetization signals (v3.5 rule E).
- csp_absent manifest content_security_policy is null; MV3 has strict default so no +2.0 penalty, but no CSP declared explicitly.
Permissions Breakdown
- search medium Allows overriding search provider; medium risk in context of NewTab override.
- chrome_url_overrides.newtab high Replaces new tab page — core monetization surface for traffic hijacking.
Pillar Scores
Permissions4.00
Reputation7.00
Network2.00
Webstore10.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 13:43
Listing SHA
f1de61480ddd…
Force block
— not fired
Score recovered
no
Elapsed
—