Hazbin Hotel Vox and Valentino Live Wallpaper
oiajcpejmmocefihegdienkheigljfhk
Risk Score
3.96
Risk Level:
Low
Recommendation:
🚫 BLOCK
Top Risks
- Uninstall URL hijack to owhit.com — classic monetization/tracking shell pattern.
- Install URL hijack to owhit.com — onInstalled opens third-party page for ad/tracking credit.
- NewTab override with 'search' permission enables search-provider monetization without disclosure.
- Privacy policy is Google's generic account policy — completely unscoped to this extension; admits data collection and 3rd-party sharing.
- Free-webmail developer (gmail) with no verified business; fan-content theme shell pattern.
Evidence
- uninstall_url_hijack crx chrome.runtime.setUninstallURL points to https://owhit.com/uninstall — third-party tracking/monetization domain.
- install_url_hijack crx onInstalled opens https://owhit.com/hazbin-hotel-vox-and-valentino-live-wallpaper — third-party URL.
- newtab_override manifest chrome_url_overrides.newtab = index.html; hijacks every new tab session.
- privacy_policy_generic store Policy URL is Google account privacy page — scope_extension=false, data_collection=true, third_party_sharing=true.
- free_webmail_developer store Developer email serdarkarayay@gmail.com; no verified business domain; domain_age_ct not queryable.
- fan_content_shell store Hazbin Hotel fan theme with 302 installs, newtab+search override — matches fan-content/theme shell pattern.
- js_external_hosts_broad crx 8 external JS hosts including owhit.com, instagram, netflix, youtube, x.com — far beyond wallpaper function.
- no_csp manifest content_security_policy is null (MV3 default applies, but no explicit restriction declared).
Permissions Breakdown
- search medium Allows querying the browser search API; paired with newtab override enables search hijack.
- chrome_url_overrides.newtab high Replaces every new tab with extension page — prime monetization and data-capture surface.
Pillar Scores
Permissions5.00
Reputation7.00
Network3.50
Webstore9.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 14:25
Listing SHA
d54391468974…
Force block
— not fired
Score recovered
no
Elapsed
—