UrbanTabs
abdiehdjhihijpamilcmfgobhggddgkk
Risk Score
5.71
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- NewTab override replaces every new tab page; controls default browsing surface for 20K users.
- Privacy policy is unscoped (scope_extension=false) and admits data collection + third-party sharing — scores maximum privacy risk.
- Extension last updated 28 months ago; stale with no changelog, increasing supply-chain risk.
- innerHTML DOM-XSS sink in newtab.8cbecc6b.js with no CSP to mitigate exploitation.
- React 16.14.0 bundled (below 16.4 threshold) with no CSP; amplifies DOM-sink risk.
Evidence
- newtab_override manifest chrome_url_overrides.newtab set; every new tab is controlled by this extension.
- privacy_policy_unscoped_with_data_sharing api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true — D-clause triggers +10.0 privacy.
- maintenance_stale store 28 months since last update; 24-36mo band scores +8.5.
- dom_xss_sink_no_csp crx innerHTML user-controlled sink in newtab JS; csp_present=false amplifies to +2.0 code quality.
- react_below_16_4_no_csp crx React 16.14.0 detected (below 16.4 threshold) with no CSP; v2 +2.0 code quality combo.
- external_js_hosts crx External JS hosts: fb.me, pxl.urbantabs.com, reactjs.org — 3 distinct domains.
- no_verified_publisher store Not a verified publisher; not featured by Google. Developer: pietechologiesinc.
- no_ratings store Rating=0 with 0 reviews at 20K installs; no social trust signal available.
Permissions Breakdown
- chrome_url_overrides.newtab medium Replaces every new tab page; controls default browsing surface for all users.
- host_permissions: *://*.urbantabs.com/* low Scoped to own domain only; limited reach beyond first-party.
Pillar Scores
Permissions3.00
Reputation5.00
Network2.00
Webstore6.00
Maintenance8.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 11:37
Listing SHA
f6067cc19862…
Force block
— not fired
Score recovered
no
Elapsed
—