Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Art Wallpapers New Tab

gpbioggjdpkjpjmedkjcjdclbllginfk
Risk Score
6.77
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category NewTab
Installs 1,000
Rating 4.5
Last updated 2023-10-19 (35 months ago)
Manifest version MV3
CSP present ✅ yes
Developer artshappen00@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy URL unreachable (fetch error); no verifiable data-handling disclosure — treated as no policy.
  • 35-month-stale NewTab extension with newtab override; near triple-stale threshold with no updates.
  • new Function() constructor and eval() in bundled JS create code-injection risk on the new-tab surface.
  • Free-webmail developer (artshappen00@gmail.com), no developer name — low accountability.
  • CSP allows unsafe-inline on script-src-elem and contacts mystart.mystartcdn.com/vmn.net (ad-tech adjacent hosts).

Evidence

  • privacy_policy_fetch_failed api Privacy policy URL returned ConnectionError; classification: fetched=false. Scored as no policy (+10.0).
  • newtab_override manifest chrome_url_overrides.newtab set; persistent reach over every new tab session.
  • stale_extension store 35 months since last update (Oct 2023); near triple-stale with NewTab monetization shape.
  • code_findings_dangerous crx new Function() in newtab/js/index.js + eval() in require.js + innerHTML DOM-XSS sink present.
  • csp_unsafe_inline_script_elem manifest CSP script-src-elem includes 'unsafe-inline' and remote CDN mystartcdn.com.
  • free_webmail_no_devname store Developer email artshappen00@gmail.com; no developer name listed; no verified publisher.
  • two_search_engines_newtab api search_engine_count=2 (google.com, yahoo.com); NewTab contacting 2 search engines (+1.5 Webstore).
  • monetization_host_telemetry api monetization_hits: google-analytics.com (telemetry tier); +1.0 Webstore.

Permissions Breakdown

  • storage low Local data persistence; low risk in isolation.
  • topSites medium Reads user's most-visited sites; privacy-sensitive for a NewTab extension.
  • chrome_url_overrides.newtab medium Replaces every new tab; persistent user-reach monetization surface.

Pillar Scores

Permissions3.00
Reputation7.50
Network5.00
Webstore5.50
Maintenance8.50
Privacy10.00
Code Quality5.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 06:15
Listing SHA 97e0b8d2c5db…
Force block — not fired
Score recovered no
Elapsed