Luffy Gear 5 One Piece Live Wallpaper
ejfeolhhbgifbjfeafeahmlnokginipa
Risk Score
6.53
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Uninstall AND install URL both hijack to gameograf.com with UTM tracking — classic traffic monetization shell.
- NewTab override contacts gameograf.com, instagram.com, netflix.com, youtube.com, x.com — unexplained external JS reach.
- Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and 3rd-party sharing.
- Developer email is free Gmail with no business domain; no verified publisher badge.
- No CSP defined (MV3 default helps, but external JS host list is broad and unexplained).
Evidence
- uninstall_url_hijack crx chrome.runtime.setUninstallURL → gameograf.com with UTM tracking params (utm_source=ovkas).
- install_url_hijack crx onInstalled opens gameograf.com with same UTM params — dual hijack pattern.
- newtab_override manifest chrome_url_overrides.newtab = index.html; combined with 'search' permission = search monetization risk.
- external_js_hosts crx JS contacts 6 external domains: gameograf.com, google.com, instagram.com, netflix.com, youtube.com, x.com.
- privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- free_webmail_developer store Developer email wilsonchristopher5534@gmail.com — no verified business domain or publisher badge.
- newtab_monetization_shape manifest NewTab + search permission + gameograf.com hijack = textbook new-tab monetization shell pattern.
- no_csp manifest content_security_policy is null; MV3 default applies but broad external host list increases exposure.
Permissions Breakdown
- search medium Allows manipulation of search provider; combined with NewTab override raises monetization risk.
- chrome_url_overrides.newtab high Replaces every new tab with extension page; primary surface for ad/search monetization.
Pillar Scores
Permissions5.00
Reputation7.50
Network4.00
Webstore10.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-15 12:36
Listing SHA
d42a66009de4…
Force block
— not fired
Score recovered
no
Elapsed
—