Tanjiro Kamado Flame Awakening Live Wallpaper
ffhbgkfolmjdodcjjfliifplkbfdhken
Risk Score
5.54
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Uninstall AND install URL both hijacked to gameograf.com — classic ad-monetization shell pattern.
- New-tab override + 'search' permission form a search-hijack surface over every new tab.
- Privacy policy is Google's generic policy (scope_extension=false, admits data collection + 3rd-party sharing) — scores maximum privacy risk.
- JS contacts gameograf.com, Instagram, Netflix, YouTube, X — 6 unrelated external hosts from a wallpaper extension.
- No CSP on MV3 extension; no code findings but external host list is anomalously broad for stated function.
Evidence
- install_url_hijack crx onInstalled opens gameograf.com with ovkas UTM tags — monetization redirect on install.
- uninstall_url_hijack crx setUninstallURL points to gameograf.com with ovkas UTM tags — 3rd-party uninstall hijack.
- newtab_override manifest chrome_url_overrides.newtab=index.html; every new tab controlled by extension.
- search_permission manifest 'search' permission declared alongside newtab override — search-hijack fingerprint.
- external_hosts_anomaly crx JS contacts gameograf.com, instagram.com, netflix.com, youtube.com, x.com — unrelated to wallpaper function.
- privacy_policy_generic store Policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- no_csp manifest content_security_policy is null; csp_present=false on MV3 extension.
- game_portal_shell store gameograf.com UTM target on both install/uninstall hooks matches game-portal shell monetization pattern.
Permissions Breakdown
- search medium Allows reading/altering search queries; combined with newtab override is a classic search-hijack pattern.
- chrome_url_overrides.newtab medium Replaces every new tab with extension-controlled page; primary surface for ad-monetization.
Pillar Scores
Permissions3.50
Reputation6.00
Network4.00
Webstore9.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 12:04
Listing SHA
1c09305a18d8…
Force block
— not fired
Score recovered
no
Elapsed
—