BirdTab - Bird Wallpapers and Nature Sounds for New Tab Page
dkdnidbnjihhilbjndnnlfipmbnoaipn
Risk Score
2.34
Risk Level:
Low
Recommendation:
✅ ALLOW
Top Risks
- NewTab override replaces every new tab — persistent, high-reach surface even with low permissions.
- No CSP declared (MV3 default applies but csp_present==false); function_constructor in 3 files elevates risk slightly.
- Privacy policy discloses third-party sharing and lacks retention details; posthog.com analytics noted.
- Developer name field empty despite verified publisher status; minor identity gap.
- search permission combined with newtab override allows search-behavior influence.
Evidence
- verified_publisher + featured store Extension carries both verified publisher badge and Google featured badge; strong governance signal.
- newtab_override manifest chrome_url_overrides.newtab = index.html; replaces every new tab page.
- function_constructor x3 crx new Function('return this') idiom in onboarding.js, background.js, quiz.js — likely bundler globalThis polyfill, not exfil.
- privacy_policy_third_party_sharing api Policy scoped to extension, data_collection=true, third_party_sharing=true, retention=false.
- posthog analytics crx eu.i.posthog.com in js_external_hosts; product analytics, no bad-host hit.
- no bad/monetization/affiliate hits api threat_intel shows empty bad_host_hits, monetization_hits, and affiliate_hits.
- host_geo_diversity api 3 countries (CA, DE, US) — below +1.5 threshold of 4.
- cve_findings_raw empty api No CVEs detected in any bundled library; CVE pillar = 0.0.
Permissions Breakdown
- storage low Standard local state persistence; no cross-site read risk.
- unlimitedStorage low Allows large local cache; typical for wallpaper/media content.
- search medium Can query browser search API; limited but non-trivial for a NewTab override.
- host: https://*.birdtab.app/* low Scoped to developer-owned domain only; low lateral risk.
- host: https://*.ingest.us.sentry.io/* low Sentry error-reporting endpoint; known telemetry provider.
- chrome_url_overrides.newtab medium Replaces every new tab; persistent reach over browsing session starts.
Pillar Scores
Permissions2.50
Reputation2.00
Network1.50
Webstore4.00
Maintenance0.00
Privacy2.00
Code Quality2.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 09:49
Listing SHA
9ed5cd275b19…
Force block
— not fired
Score recovered
no
Elapsed
—