Stitch Cosmic Adventure Live Wallpaper
jdefbooiojcicffaodmdoajbdjbfhffb
Risk Score
6.14
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Uninstall and install URL both hijacked to gameograf.com — confirmed monetization shell pattern.
- NewTab override with search permission enables persistent search/ad revenue capture on every new tab.
- Privacy policy URL unreachable (fetch_error); treated as no policy — full +10 privacy score.
- Free-webmail developer (gmail), no developer name, no verified business domain — low accountability.
- Extension contacts google.com, instagram.com, netflix.com, youtube.com, x.com from JS — broad outbound reach.
Evidence
- uninstall_url_hijack crx chrome.runtime.setUninstallURL → gameograf.com with ovkas UTM params; classic monetization redirect.
- install_url_hijack crx onInstalled opens gameograf.com with ovkas UTM params; confirms traffic-monetization intent.
- newtab_override manifest chrome_url_overrides.newtab set to index.html; every new tab controlled by extension.
- privacy_policy_unreachable api fetch_error:ConnectionError on https://ovkas.com/privacy-policy; policy treated as absent.
- free_webmail_no_devname store Developer email halilseker3455@gmail.com; developer_name empty; no verified business domain.
- js_external_hosts_broad crx Extension JS contacts gameograf.com, games.ovkas.com, instagram.com, netflix.com, youtube.com, x.com.
- verified_publisher_low_value store verified_publisher=true but dev is free-webmail with no name; verification provides limited assurance.
- newtab_monetization_shape crx NewTab + search permission + install/uninstall hijack to ad-UTM URL = textbook traffic-monetization cluster.
Permissions Breakdown
- search medium Allows querying browser search; combined with newtab override, enables search monetization.
- chrome_url_overrides.newtab high Replaces every new tab with extension page; prime surface for ad injection and search hijacking.
Pillar Scores
Permissions4.50
Reputation7.50
Network2.50
Webstore10.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 05:10
Listing SHA
a41093501967…
Force block
— not fired
Score recovered
no
Elapsed
—