Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Tabrr Dashboard - New Tab with AI

ehmneimbopigfgchjglgngamiccjkijh
Risk Score
5.54
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category NewTab
Installs 50,000
Rating 4.5
Last updated 2025-08-12 (12 months ago)
Manifest version MV3
CSP present ❌ no
Developer jjamesmake13@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection and third-party sharing but is not scoped to this extension → Privacy pillar maxed at 10.
  • scripting + <all_urls> allows arbitrary JS injection into every site; NewTab override adds broad reach.
  • new Function() constructor in background.js and previewMaker.js with no CSP is a dynamic code execution risk.
  • Free-webmail developer email (gmail) with no developer name reduces accountability.
  • AI/NewTab category with <all_urls> and unscoped data-sharing policy creates high option value for future abuse.

Evidence

  • privacy_policy_unscoped_with_third_party_sharing api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → D-clause applies, score +10.
  • scripting+all_urls manifest scripting permission paired with <all_urls> host_permission; can inject JS on every site.
  • newtab_override manifest chrome_url_overrides.newtab replaces new-tab page; high reach for 50K users.
  • function_constructor_no_csp crx new Function() in background.js and previewMaker.js; csp_present=false amplifies risk.
  • developer_email_free_webmail store Developer email jjamesmake13@gmail.com; no developer name provided; reduces accountability.
  • verified_publisher_featured store Extension is verified_publisher and is_featured_by_google; partially mitigates reputation risk.
  • js_external_hosts_diverse crx 12 distinct external hosts including third-party commerce/social sites; >3 registrable domains.
  • no_csp_mv3 manifest content_security_policy is null; no explicit CSP despite dynamic code usage.

Permissions Breakdown

  • storage low Standard local data persistence; low risk.
  • tabs medium Can read URLs/titles of open tabs; moderate privacy risk.
  • scripting high Allows arbitrary JS injection into pages; amplified by <all_urls>.
  • unlimitedStorage low Removes storage quota; low standalone risk.
  • alarms low Scheduling only; minimal risk.
  • search medium Can query the browser search engine; moderate risk for a NewTab override.
  • <all_urls> (host_permission) high Broad host access enables scripting+fetch on every site visited.
  • newtab override (chrome_url_overrides) medium Replaces new-tab page; significant reach and monetization vector.

Pillar Scores

Permissions7.50
Reputation4.00
Network3.50
Webstore5.50
Maintenance3.50
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 07:50
Listing SHA dca8d3f3312d…
Force block — not fired
Score recovered no
Elapsed