Los Angeles Lakers Wallpaper
knpfogcgbkopnbphmgblkgneephoggml
Risk Score
5.88
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Uninstall URL hijack to owhit.com and install URL hijack — classic monetization-shell pattern.
- Privacy policy is generic Google account policy, not scoped to this extension; admits data collection and 3rd-party sharing.
- Free-webmail developer (gmail) with no verified business identity; no verified-publisher badge.
- NewTab override with search permission — high potential for search/ad monetization on every new tab.
- 8 external JS hosts (owhit.com, instagram, netflix, youtube, x.com, etc.) with no CSP; broad network reach from a wallpaper extension.
Evidence
- uninstall_url_hijack crx chrome.runtime.setUninstallURL points to https://owhit.com/uninstall — 3rd-party monetization domain.
- install_url_hijack crx onInstalled opens https://owhit.com/los-angeles-lakers-wallpaper — 3rd-party domain engagement on install.
- newtab_override manifest chrome_url_overrides.newtab = index.html; replaces every new tab with developer-controlled page.
- generic_privacy_policy store Privacy policy is Google account policy (scope_extension=false, data_collection=true, third_party_sharing=true).
- free_webmail_dev store Developer email yusufkerem050@gmail.com; no verified publisher, no business domain.
- js_external_hosts crx 8 external hosts including owhit.com, instagram, netflix, youtube, x.com — excessive for a wallpaper/newtab.
- no_csp crx content_security_policy is null; no CSP protection on MV3 extension.
- search_permission_newtab manifest search permission combined with newtab override enables search provider manipulation for monetization.
Permissions Breakdown
- search medium Allows overriding search provider; medium-risk for search hijacking potential.
- chrome_url_overrides.newtab medium Replaces new tab page; primary surface for monetization/ad injection on every new tab.
Pillar Scores
Permissions3.30
Reputation7.50
Network2.00
Webstore10.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 14:39
Listing SHA
15e49f091daa…
Force block
— not fired
Score recovered
no
Elapsed
—