Chibi Tanjiro and Nezuko Autumn Breeze Live Wallpaper
okghffpbjoabbimlhcmdpejhghbegfcn
Risk Score
5.66
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- Uninstall and install URL hijack to gameograf.com — confirmed monetization shell/game-portal pattern.
- Privacy policy is generic Google account policy (scope_extension=false, data_collection=true, third_party_sharing=true) — worst-case privacy score.
- New-tab override with external JS contacts google.com, instagram.com, netflix.com, youtube.com, x.com — excessive reach for a wallpaper.
- Free-webmail developer (gmail), no developer name, no verified business domain — low accountability.
- gameograf.com UTM tracking across install/uninstall hooks indicates ad-monetization operator.
Evidence
- uninstall_url_hijack manifest chrome.runtime.setUninstallURL → gameograf.com with UTM params; game-portal monetization shell confirmed.
- install_url_hijack manifest onInstalled opens gameograf.com with UTM params; same domain as uninstall URL.
- newtab_override manifest chrome_url_overrides.newtab = index.html; replaces every new tab for all users.
- privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- external_js_hosts crx JS contacts gameograf.com, instagram.com, netflix.com, youtube.com, x.com — unrelated to wallpaper function.
- developer_identity store developer_name empty, email is free Gmail, no business domain — zero accountability.
- verified_publisher store verified_publisher=true but monetization hooks present; v3.5(E) caps discount to -1.0.
- cve_findings crx jquery 3.7.1 bundled; cve_findings_raw empty — no known CVEs at this version.
Permissions Breakdown
- search medium Allows search provider queries; paired with newtab override elevates risk.
- chrome_url_overrides.newtab medium Replaces new tab page; primary monetization vector for this extension type.
Pillar Scores
Permissions3.00
Reputation6.50
Network2.00
Webstore10.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-15 14:19
Listing SHA
4bf22c31bc2f…
Force block
— not fired
Score recovered
no
Elapsed
—