Cute Cinnamoroll Live Wallpaper
kjgedifallckelddhiialgfibjkdmmmi
Risk Score
3.87
Risk Level:
Low
Recommendation:
🚫 BLOCK
Top Risks
- Uninstall URL hijacked to owhit.com — classic monetization/tracking shell pattern
- Install URL hijacked to owhit.com — opens 3rd-party page on every install
- Privacy policy is generic Google account policy, not scoped to this extension; admits data collection and 3rd-party sharing
- NewTab override + search permission = full new-tab search hijack capability; JS contacts Netflix, Instagram, YouTube, X, OpenAI
- Free-webmail developer (dermanseven32@gmail.com) with no verified identity or business domain
Evidence
- uninstall_url_hijack manifest chrome.runtime.setUninstallURL targets https://owhit.com/uninstall — 3rd-party redirect on uninstall.
- install_url_hijack manifest onInstalled opens https://owhit.com/cute-cinnamoroll-live-wallpaper/ — 3rd-party page opened on install.
- newtab_override manifest chrome_url_overrides.newtab = index.html; replaces every new tab for all users.
- privacy_policy_generic store Policy URL is Google account policy (scope_extension=false, data_collection=true, third_party_sharing=true).
- free_webmail_developer store Developer email dermanseven32@gmail.com; developer_name='backgrounds'; no verifiable business identity.
- js_external_hosts crx JS references chat.openai.com, instagram.com, netflix.com, x.com, youtube.com, owhit.com — broad unrelated reach.
- no_csp manifest content_security_policy is null; MV3 default applies but no explicit CSP declared.
- search_permission_plus_newtab manifest Combination of 'search' permission and newtab override enables full search-provider hijack.
Permissions Breakdown
- search medium Allows querying browser search engine; combined with newtab override creates full search hijack surface.
- chrome_url_overrides.newtab high Replaces every new tab page; primary monetization/surveillance surface for this category.
Pillar Scores
Permissions4.00
Reputation7.50
Network4.50
Webstore8.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 15:34
Listing SHA
60d5e970c4d1…
Force block
— not fired
Score recovered
no
Elapsed
—