Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

SuperStart New Tab Page

eajimemccdpladcgbfeideelblbkiclc
Risk Score
3.58
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category NewTab
Installs 10,000
Rating 4.5
Last updated 2026-06-13
Manifest version MV3
CSP present ✅ yes
Developer contact@amplebyte.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but does NOT scope to this extension AND admits data collection + third-party sharing — scores maximum privacy risk.
  • NewTab override replaces every new tab; high daily reach despite low install count.
  • No developer name listed; identity accountability gap.
  • CSP allows localhost:8097 (dev React DevTools port) in production build.
  • react@16.13.1 bundled — below 16.4 DOM-manipulation threshold used in CVE v2 amplifier (no CVEs found, but version is old).

Evidence

  • privacy_policy_admits_collection_and_3p_sharing_without_extension_scope api privacy_policy_classification: fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy pillar (v3.5 rule D).
  • newtab_override_declared manifest chrome_url_overrides.newtab=index.html; every new tab served by extension for 10K users.
  • verified_publisher_and_featured store verified_publisher=true AND is_featured_by_google=true; discounts applied, reputation floor 2.0.
  • csp_localhost_in_production crx CSP script-src includes http://localhost:8097 — React DevTools debug endpoint left in prod build.
  • react_16_13_1_bundled crx react@16.13.1 detected; below 16.4 threshold. No CVEs found in cve_findings_raw.
  • no_bad_hosts_no_affiliate_no_monetization api threat_intel: bad_host_hits=[], affiliate_hits=[], monetization_hits=[]; single search engine google.com.
  • no_code_findings_no_obfuscation crx code_findings_raw=[], obfuscation_score=0.0; all 9 JS files scanned cleanly.
  • developer_name_missing store developer_name is empty string; identity accountability reduced despite verified publisher status.

Permissions Breakdown

  • tabs medium Can read tab URLs and titles; moderate risk for session enumeration.
  • storage low Local preference storage; standard for new-tab customization.
  • unlimitedStorage low Extends storage quota; no direct privacy risk.
  • sessions medium Access to recently closed tabs/sessions; can read browsing history context.
  • system.cpu low Read-only CPU stats; low impact, typical for dashboard widgets.
  • system.memory low Read-only memory stats; low impact, typical for dashboard widgets.
  • chrome_url_overrides.newtab medium Replaces new-tab page; high daily reach and monetization risk surface.

Pillar Scores

Permissions3.30
Reputation2.00
Network0.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:29
Listing SHA b7189adf455b…
Force block — not fired
Score recovered no
Elapsed 26.0s