One Piece Boat Live Wallpaper
mfiokjilbklopaebiaepoiaogibobiaf
Risk Score
6.27
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Uninstall and install URL hijacks redirect to gameograf.com — confirmed ad-monetization shell pattern.
- NewTab override replaces every new tab; JS contacts social/streaming platforms (Instagram, Netflix, YouTube, X) with no stated reason.
- Privacy policy is Google's generic policy — scope_extension=false, data_collection=true, third_party_sharing=true; worst-case +10 privacy.
- Free-webmail dev (gmail), no developer name, verified_publisher flag inconsistent with throwaway identity signals.
- No CSP on MV3 extension with external JS hosts spanning 6 distinct domains.
Evidence
- install_url_hijack + uninstall_url_hijack manifest Both onInstalled and uninstall redirect to gameograf.com with UTM tracking — textbook monetization shell.
- chrome_url_overrides.newtab manifest Overrides every new tab with index.html — high-reach surface for ad injection.
- js_external_hosts crx Extension contacts gameograf.com, instagram.com, netflix.com, youtube.com, x.com — unrelated to wallpaper function.
- privacy_policy_generic store Policy URL is Google Account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- free_webmail_no_dev_name store Developer email halilseker3455@gmail.com with no developer_name; numbered-alias pattern.
- no_csp manifest content_security_policy is null; no CSP despite 6 external JS hosts.
- new_tab_override_monetization manifest NewTab override combined with install/uninstall hijack to ad-tracking URL is a known monetization cluster.
- operator_cluster_singleton api sibling_count=0 but fingerprint ties to gameograf.com ad-tracking infrastructure.
Permissions Breakdown
- search medium Allows reading/overriding search queries; medium risk in a NewTab shell.
- chrome_url_overrides.newtab high Replaces every new tab — high reach, ad-monetization surface.
Pillar Scores
Permissions4.00
Reputation7.00
Network4.50
Webstore10.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 04:40
Listing SHA
b72f6c0d0002…
Force block
— not fired
Score recovered
no
Elapsed
—