Sung Jin Woo Wallpaper
ppglgkahhghnjifmjhdlhpaeppkpffpi
Risk Score
5.64
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Uninstall URL hijack to owhit.com and install URL hijack: explicit monetization/tracking shell pattern.
- Privacy policy is Google's generic policy — scope_extension==false with data_collection+third_party_sharing admitted: scores maximum privacy risk.
- NewTab override combined with 'search' permission and gmail dev with no verified publisher — classic fan-content monetization shell.
- Free-webmail developer (gmail), no verified publisher, no business domain — low accountability.
- 8 external JS hosts contacted including Netflix, Instagram, YouTube, X — broad reach beyond stated wallpaper function.
Evidence
- uninstall_url_hijack crx chrome.runtime.setUninstallURL → https://owhit.com/uninstall; monetization shell indicator.
- install_url_hijack crx onInstalled opens https://owhit.com/sung-jin-woo-wallpaper; 3rd-party redirect on install.
- privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- newtab_override manifest chrome_url_overrides.newtab = index.html; replaces every new tab for all users.
- free_webmail_dev store Developer email gokturksener476@gmail.com; no verified publisher; no business website.
- external_hosts_broad crx JS contacts 8 external hosts: owhit.com, chatgpt.com, netflix.com, instagram.com, youtube.com, x.com, etc.
- new_tab_monetization_shape store NewTab + search override + uninstall hijack + fan-content title = monetization shell fingerprint.
- no_csp manifest content_security_policy is null; MV3 default applies but no explicit CSP declared.
Permissions Breakdown
- search medium Allows overriding search provider; medium risk on its own.
- chrome_url_overrides.newtab medium Replaces new tab page — classic monetization surface for ad/redirect injection.
Pillar Scores
Permissions3.50
Reputation7.50
Network2.00
Webstore10.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 14:11
Listing SHA
2c7cbaaa5c24…
Force block
— not fired
Score recovered
no
Elapsed
—