Is WebStart+ New Tab safe?
WebStart+ New Tab is medium risk. The extension makes a random 32-char ID on install, stores it, and sends it over plain HTTP to ping.webstart.page: on install, daily, and on updates, with the extension ID, version, and a channel code. Anyone on the path can read it.
Who publishes itdev - 1 other listing from the same operator, none carrying a finding
dev - 1 other listing from the same operator, none carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
1 other listing published from this account, 60k+ users between them, none of them carrying a finding.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
New-tab extension pings persistent device ID over unencrypted HTTP
The extension makes a random 32-char ID on install, stores it, and sends it over plain HTTP to ping.webstart.page: on install, daily, and on updates, with the extension ID, version, and a channel code.
Anyone on the path can read it.
You install or update the new-tab extension, or a day passes after installation.
No user interaction is needed for the daily ping, the extension fires it automatically.
The extension transmits a persistent device identifier, your extension ID, and version number to ping.webstart.page over plain HTTP.
The request uses HTTP, not HTTPS, so the device identifier and other parameters are visible in cleartext on the network.
| Field | Value | Why it matters | |
|---|---|---|---|
Device identifier (mid) | A3F2B1C9D4E07865F1A2B3C4D5E6F708 | A 32-character random hex ID made on first install, stored permanently, and resent on every ping so the server can track this install. | |
Extension ID (ex) | kpdnpadaadhikjpaegjbmambpdincpgi | The browser-assigned identifier for the extension, confirming which product is installed. | |
Extension version (ver) | 1.0.0.0 | The installed version number of the extension. | |
Distribution channel (ch) | organic | A code identifying which marketing channel or bundle the extension was installed from. | |
Variant / distribution ID (vid) | 1 | A numeric value read from a cookie on defaults.webstart.page at install time, tracking which variant or referral source the user came from. | |
Event type (s) | 1 | Indicates whether this ping is for a new install (1), daily check-in (2), or extension update (3). |
After the initial install ping, the extension sets a chrome.alarms entry that fires every 1440 minutes (24 hours). Each firing sends the device ID and parameters to ping.webstart.page over HTTP for as long as the extension remains installed.
Machine ID generation and ping dispatch (scripts/ping.js)
// guid() generates a 32-char hex string and persists it as 'machineId' // in chrome.storage.local. On subsequent calls the stored value is reused, // so the same ID is sent every time regardless of when the ping fires. // SendPingDetails is called with: // status=1 on install, status=2 on daily alarm, status=3 on update // The resulting URL uses http:// — no TLS — so mid, ex, ver, and ch // are transmitted in cleartext over the network.
- ping.webstart.page
Operator analytics endpoint. Receives device ID, extension ID, version, channel, and event type on install, daily, and on each extension update. Connection is over plain HTTP.
- defaults.webstart.page
Checked for vid and channel cookies at install time to record the referral source. Cookies are read and then deleted from browser storage.
What it can do
Permissions this extension asks for, as declared in version 1.0.0.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on webstart.page
https://*.webstart.page/chrome*
Read the sites you visit most
topSites
Store data in your browser
storage
Read and change cookies, including the ones that keep you signed in
cookies
Schedule its own background tasks
alarms