Itachi Uchiha Moonlight Crow Live Wallpaper
flokabnmchfbagkeapipekgmdiagnljo
Risk Score
5.72
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- Uninstall and install URL both hijacked to gameograf.com — confirmed monetization shell pattern.
- Privacy policy is Google's generic account policy; does not scope to this extension at all, admits data+3rd-party sharing.
- NewTab override + search permission = search-engine hijacking surface on every new tab.
- Developer email is free webmail (gmail), no developer name, no business domain — identity unverifiable.
- JS contacts gameograf.com, instagram.com, netflix.com, youtube.com, x.com — 5+ unrelated origins.
Evidence
- uninstall_url_hijack manifest chrome.runtime.setUninstallURL → gameograf.com with UTM params; classic monetization shell.
- install_url_hijack manifest onInstalled opens gameograf.com with UTM params — traffic monetization on install.
- newtab_override manifest chrome_url_overrides.newtab = index.html; every new tab controlled by extension.
- privacy_policy_generic store Policy URL is myaccount.google.com/privacypolicy — Google's own policy, scope_extension=false, admits 3rd-party sharing.
- js_external_hosts crx 6 external JS hosts: gameograf.com, google.com, instagram.com, netflix.com, youtube.com, x.com.
- free_webmail_no_devname store developer_name empty, email halilseker3455@gmail.com — no verifiable business identity.
- new_tab_monetization_shape store NewTab + uninstall/install hijack + gameograf.com = textbook low-effort traffic-monetization cluster.
- verified_publisher store Verified publisher badge present but email is free webmail; discount capped due to monetization pattern.
Permissions Breakdown
- search medium Allows search provider manipulation; paired with newtab override amplifies monetization risk.
- chrome_url_overrides.newtab high Replaces every new-tab page; core vector for ad-monetization and search hijacking.
Pillar Scores
Permissions4.00
Reputation6.50
Network2.00
Webstore10.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 12:28
Listing SHA
6871d172edeb…
Force block
— not fired
Score recovered
no
Elapsed
—