Nahida Genshin Impact Live Wallpaper
pgkncffoffbpibiaacejfphdmnmgbfhm
Risk Score
5.72
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Uninstall URL hijack redirects to gameograf.com — classic monetization shell fingerprint.
- Install URL hijack opens gameograf.com on installation — install-redirect pattern.
- NewTab override with 'search' permission is a known ad-monetization vector.
- Privacy policy timed out during fetch — privacy obligations completely unverifiable.
- No developer name listed; 9 external JS hosts including social/streaming platforms with no stated purpose.
Evidence
- uninstall_url_hijack manifest setUninstallURL → https://gameograf.com/?utm_source=gameograf (3rd-party monetization domain).
- install_url_hijack manifest onInstalled opens https://gameograf.com/?utm_source=install — install redirect to 3rd party.
- newtab_override manifest chrome_url_overrides.newtab = newtab.html; combined with 'search' permission = search monetization pattern.
- privacy_policy_fetch_error api privacy_policy_classification.fetched==false (ReadTimeout); policy unverifiable → +10.0 privacy pillar.
- external_js_hosts crx 9 external hosts: chatgpt.com, gameograf.com, google.com, instagram.com, netflix.com, reddit.com, youtube.com, x.com, chrome.google.com.
- no_developer_name store developer_name is empty string; verified publisher badge present but no display name.
- stale_extension store 16 months since last update; maintenance score +6.0 (6-12mo band).
- verified_publisher store verified_publisher==true; discount capped at -1.0 per invariant 0c/v3.5E (monetization hits present via gameograf install/uninstall URLs).
Permissions Breakdown
- search medium Allows manipulation of search provider; medium risk on its own, but paired with newtab override raises concern.
- chrome_url_overrides.newtab medium Replaces new-tab page; classic monetization vector for ad-injection and search hijacking.
Pillar Scores
Permissions3.50
Reputation5.00
Network2.00
Webstore8.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 04:55
Listing SHA
d7801638d070…
Force block
— not fired
Score recovered
no
Elapsed
—