SuperStart New Tab Page
eajimemccdpladcgbfeideelblbkiclc
Risk Score
3.58
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy fetched but does NOT scope to this extension AND admits data collection + third-party sharing — scores maximum privacy risk.
- NewTab override replaces every new tab; high daily reach despite low install count.
- No developer name listed; identity accountability gap.
- CSP allows localhost:8097 (dev React DevTools port) in production build.
- react@16.13.1 bundled — below 16.4 DOM-manipulation threshold used in CVE v2 amplifier (no CVEs found, but version is old).
Evidence
- privacy_policy_admits_collection_and_3p_sharing_without_extension_scope api privacy_policy_classification: fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy pillar (v3.5 rule D).
- newtab_override_declared manifest chrome_url_overrides.newtab=index.html; every new tab served by extension for 10K users.
- verified_publisher_and_featured store verified_publisher=true AND is_featured_by_google=true; discounts applied, reputation floor 2.0.
- csp_localhost_in_production crx CSP script-src includes http://localhost:8097 — React DevTools debug endpoint left in prod build.
- react_16_13_1_bundled crx react@16.13.1 detected; below 16.4 threshold. No CVEs found in cve_findings_raw.
- no_bad_hosts_no_affiliate_no_monetization api threat_intel: bad_host_hits=[], affiliate_hits=[], monetization_hits=[]; single search engine google.com.
- no_code_findings_no_obfuscation crx code_findings_raw=[], obfuscation_score=0.0; all 9 JS files scanned cleanly.
- developer_name_missing store developer_name is empty string; identity accountability reduced despite verified publisher status.
Permissions Breakdown
- tabs medium Can read tab URLs and titles; moderate risk for session enumeration.
- storage low Local preference storage; standard for new-tab customization.
- unlimitedStorage low Extends storage quota; no direct privacy risk.
- sessions medium Access to recently closed tabs/sessions; can read browsing history context.
- system.cpu low Read-only CPU stats; low impact, typical for dashboard widgets.
- system.memory low Read-only memory stats; low impact, typical for dashboard widgets.
- chrome_url_overrides.newtab medium Replaces new-tab page; high daily reach and monetization risk surface.
Pillar Scores
Permissions3.30
Reputation2.00
Network0.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:29
Listing SHA
b7189adf455b…
Force block
— not fired
Score recovered
no
Elapsed
26.0s