Nick & Judy Live Wallpaper
iipaiidhmpmiokjkjkfbncfefljbbjec
Risk Score
6.15
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Uninstall URL hijack routes to gameograf.com ad-campaign — confirmed monetization shell pattern
- Install URL hijack to same ad-campaign domain on every install event
- NewTab override + search permission = full search-traffic monetization capability
- Privacy policy URL returns fetch error (unfetchable); no effective data-handling disclosure
- Free-webmail dev (gmail), no developer name, no verifiable business identity
Evidence
- uninstall_url_hijack manifest setUninstallURL targets gameograf.com with UTM campaign params — classic monetization shell uninstall redirect.
- install_url_hijack manifest onInstalled opens gameograf.com with same UTM params — ad-traffic acquisition on every install.
- newtab_override manifest chrome_url_overrides.newtab set to index.html; combined with 'search' permission enables search hijacking.
- privacy_policy_unfetchable api ovkas.com/privacy-policy/ returns HTTPError; policy cannot be evaluated — treated as no policy.
- free_webmail_no_dev_name store Developer email halilseker3455@gmail.com, developer_name empty — no verifiable business identity.
- js_external_hosts_social crx Extension contacts gameograf.com, instagram.com, netflix.com, youtube.com, x.com — broad social/media reach from wallpaper.
- verified_publisher store Verified publisher badge present, but 0c cap applies: monetization hits (gameograf.com) limit discount to -1.0.
- game_portal_shell store gameograf.com is a game portal domain; uninstall+install hijack pattern matches game-portal shell fingerprint.
Permissions Breakdown
- search medium Allows manipulation of search queries/provider; paired with newtab override is a monetization vector.
- chrome_url_overrides.newtab high Replaces every new tab with extension-controlled page; core mechanism for search-traffic hijacking.
Pillar Scores
Permissions5.00
Reputation7.50
Network2.00
Webstore10.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-16 04:20
Listing SHA
dc4bab3f81a0…
Force block
— not fired
Score recovered
no
Elapsed
—