Dodge Challenger Live Wallpaper
lfijgllpkfddkeeedjkkealjbicdhcom
Risk Score
5.79
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Uninstall and install URL hijacks both redirect to gameograf.com with tracking UTM params — clear monetization shell.
- New-tab override combined with search permission enables ad-monetization on every new tab.
- Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and third-party sharing.
- Free-webmail developer (gmail) with no developer name and no business website; identity unverifiable.
- JS external hosts include gameograf.com alongside major platforms; no CSP to constrain script execution.
Evidence
- uninstall_url_hijack manifest setUninstallURL → gameograf.com with ovkas UTM params; canonical monetization-shell indicator.
- install_url_hijack manifest onInstalled opens gameograf.com with same UTM tracking; double hijack pattern.
- newtab_override manifest chrome_url_overrides.newtab = index.html; replaces every new tab for ad delivery.
- privacy_policy_generic store Policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- free_webmail_no_dev_name store developer_email=halilseker3455@gmail.com; developer_name empty; no verifiable business identity.
- external_hosts crx JS contacts gameograf.com plus google/instagram/netflix/youtube/x.com; no CSP present.
- csp_absent_mv3 manifest content_security_policy is null on MV3; no script-src restriction despite 3 JS files.
- verified_publisher_with_monetization store verified_publisher=true but uninstall/install URL hijacks to gameograf.com cap discount to -1.0 per v3.5(E).
Permissions Breakdown
- search medium Allows overriding default search; paired with newtab override increases monetization risk.
- chrome_url_overrides.newtab high Replaces every new tab page — primary monetization surface for this shell pattern.
Pillar Scores
Permissions5.00
Reputation7.00
Network2.00
Webstore10.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 09:43
Listing SHA
d5cd14469cfb…
Force block
— not fired
Score recovered
no
Elapsed
—