Tabrr Dashboard - New Tab with AI
ehmneimbopigfgchjglgngamiccjkijh
Risk Score
5.54
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy admits data collection and third-party sharing but is not scoped to this extension → Privacy pillar maxed at 10.
- scripting + <all_urls> allows arbitrary JS injection into every site; NewTab override adds broad reach.
- new Function() constructor in background.js and previewMaker.js with no CSP is a dynamic code execution risk.
- Free-webmail developer email (gmail) with no developer name reduces accountability.
- AI/NewTab category with <all_urls> and unscoped data-sharing policy creates high option value for future abuse.
Evidence
- privacy_policy_unscoped_with_third_party_sharing api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → D-clause applies, score +10.
- scripting+all_urls manifest scripting permission paired with <all_urls> host_permission; can inject JS on every site.
- newtab_override manifest chrome_url_overrides.newtab replaces new-tab page; high reach for 50K users.
- function_constructor_no_csp crx new Function() in background.js and previewMaker.js; csp_present=false amplifies risk.
- developer_email_free_webmail store Developer email jjamesmake13@gmail.com; no developer name provided; reduces accountability.
- verified_publisher_featured store Extension is verified_publisher and is_featured_by_google; partially mitigates reputation risk.
- js_external_hosts_diverse crx 12 distinct external hosts including third-party commerce/social sites; >3 registrable domains.
- no_csp_mv3 manifest content_security_policy is null; no explicit CSP despite dynamic code usage.
Permissions Breakdown
- storage low Standard local data persistence; low risk.
- tabs medium Can read URLs/titles of open tabs; moderate privacy risk.
- scripting high Allows arbitrary JS injection into pages; amplified by <all_urls>.
- unlimitedStorage low Removes storage quota; low standalone risk.
- alarms low Scheduling only; minimal risk.
- search medium Can query the browser search engine; moderate risk for a NewTab override.
- <all_urls> (host_permission) high Broad host access enables scripting+fetch on every site visited.
- newtab override (chrome_url_overrides) medium Replaces new-tab page; significant reach and monetization vector.
Pillar Scores
Permissions7.50
Reputation4.00
Network3.50
Webstore5.50
Maintenance3.50
Privacy10.00
Code Quality2.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 07:50
Listing SHA
dca8d3f3312d…
Force block
— not fired
Score recovered
no
Elapsed
—