Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

UrbanTabs

abdiehdjhihijpamilcmfgobhggddgkk
Risk Score
5.71
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category NewTab
Installs 20,000
Rating
Last updated 2024-04-18 (28 months ago)
Manifest version MV3
CSP present ❌ no
Developer contact@urbantabs.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • NewTab override replaces every new tab page; controls default browsing surface for 20K users.
  • Privacy policy is unscoped (scope_extension=false) and admits data collection + third-party sharing — scores maximum privacy risk.
  • Extension last updated 28 months ago; stale with no changelog, increasing supply-chain risk.
  • innerHTML DOM-XSS sink in newtab.8cbecc6b.js with no CSP to mitigate exploitation.
  • React 16.14.0 bundled (below 16.4 threshold) with no CSP; amplifies DOM-sink risk.

Evidence

  • newtab_override manifest chrome_url_overrides.newtab set; every new tab is controlled by this extension.
  • privacy_policy_unscoped_with_data_sharing api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true — D-clause triggers +10.0 privacy.
  • maintenance_stale store 28 months since last update; 24-36mo band scores +8.5.
  • dom_xss_sink_no_csp crx innerHTML user-controlled sink in newtab JS; csp_present=false amplifies to +2.0 code quality.
  • react_below_16_4_no_csp crx React 16.14.0 detected (below 16.4 threshold) with no CSP; v2 +2.0 code quality combo.
  • external_js_hosts crx External JS hosts: fb.me, pxl.urbantabs.com, reactjs.org — 3 distinct domains.
  • no_verified_publisher store Not a verified publisher; not featured by Google. Developer: pietechologiesinc.
  • no_ratings store Rating=0 with 0 reviews at 20K installs; no social trust signal available.

Permissions Breakdown

  • chrome_url_overrides.newtab medium Replaces every new tab page; controls default browsing surface for all users.
  • host_permissions: *://*.urbantabs.com/* low Scoped to own domain only; limited reach beyond first-party.

Pillar Scores

Permissions3.00
Reputation5.00
Network2.00
Webstore6.00
Maintenance8.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 11:37
Listing SHA f6067cc19862…
Force block — not fired
Score recovered no
Elapsed