Mercedes GT 63 S Live Wallpaper
gfnjnaibjiiclafhbhcfdchiieoljlhl
Risk Score
3.38
Risk Level:
Low
Recommendation:
🚫 BLOCK
Top Risks
- Uninstall URL hijack to owhit.com — classic low-effort traffic-monetization shell pattern
- Install URL hijack to owhit.com — redirects users to 3rd-party page on install
- New-tab override combined with search permission enables search-revenue hijacking
- Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection & 3rd-party sharing
- Free-webmail developer (gmail) with no verified business; 8 external JS hosts including major platforms
Evidence
- uninstall_url_hijack crx chrome.runtime.setUninstallURL -> https://owhit.com/uninstall; classic monetization shell pattern (+3.0 Webstore)
- install_url_hijack crx onInstalled opens https://owhit.com/mercedes-gt-63-s-live-wallpaper (+2.0 Webstore)
- newtab_override manifest chrome_url_overrides.newtab=index.html replaces new-tab page; +2.0 Webstore (newtab+monetization shape)
- generic_privacy_policy store Policy is Google account policy: scope_extension=false, data_collection=true, third_party_sharing=true -> +10.0 Privacy (v3.5 D)
- free_webmail_developer store Developer email acelyasereflerim@gmail.com; no verified business website; Reputation floor 7.5
- external_js_hosts crx 8 external JS hosts: owhit.com, chat.openai.com, instagram.com, netflix.com, youtube.com, x.com, google.com, chrome.google.com
- search_permission_plus_newtab manifest search permission + newtab override = monetization-aligned capability pair
- csp_absent_mv3 manifest content_security_policy null; MV3 has strict default so no v2.1(b) penalty applied
Permissions Breakdown
- search medium Can interact with search provider settings; paired with newtab override raises monetization risk.
- chrome_url_overrides.newtab high Replaces new-tab page entirely; primary vector for ad-monetization and search hijacking.
Pillar Scores
Permissions2.00
Reputation7.50
Network2.50
Webstore10.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 18:44
Listing SHA
9f8a236d3c37…
Force block
— not fired
Score recovered
no
Elapsed
—