Networthy
gejjohmabbknpioegdacnhpcplfdflgj
Risk Score
6.21
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- NewTab override replaces every new tab with arcade game; prime monetization/injection surface.
- Privacy policy is Google's generic policy — not scoped to this extension, admits data collection & 3rd-party sharing → +10.0 privacy pillar.
- 34 months without update (>24mo stale) on an active newtab extension is a takeover risk.
- Developer uses free webmail (proton.me), no business website, no verified publisher badge.
- 5 external JS hosts (getbootstrap.com, github.com, goo.gl, popper.js.org, charistheo.io) loaded without CSP — remote code injection risk.
Evidence
- newtab_override manifest chrome_url_overrides.newtab → override_page.html; every new tab hijacked.
- generic_google_privacy_policy store Privacy URL is myaccount.google.com/privacypolicy; scope_extension=false, data_collection=true, third_party_sharing=true.
- stale_extension store Last updated November 2023; 34 months since update — zombie risk.
- free_webmail_developer store Developer email gameoftoday@proton.me; free webmail, no business domain, not verified.
- external_js_hosts_no_csp crx 5 external JS hosts (getbootstrap.com, github.com, goo.gl, popper.js.org, charistheo.io); CSP absent.
- description_shell_pattern store description_promise.is_shell_pattern=true; description says arcade game but deploys newtab override.
- no_install_count store Install count not available; reach unknown.
- no_cve_findings crx cve_findings_raw empty; no known CVEs detected in bundled libraries.
Permissions Breakdown
- chrome_url_overrides.newtab medium Replaces new-tab page; monetization surface, scoped to override_page.html.
Pillar Scores
Permissions2.00
Reputation7.50
Network3.00
Webstore8.00
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 08:27
Listing SHA
a1923a4b8f04…
Force block
— not fired
Score recovered
no
Elapsed
—