Is WebStart+ New Tab safe?

Medium risk

WebStart+ New Tab is medium risk. The extension makes a random 32-char ID on install, stores it, and sends it over plain HTTP to ping.webstart.page: on install, daily, and on updates, with the extension ID, version, and a channel code. Anyone on the path can read it.

devv1.0.0.0Chrome Web Store
45Risk
Who publishes it

dev - 1 other listing from the same operator, none carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
dev

Same store account

1 other listing published from this account, 60k+ users between them, none of them carrying a finding.

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

New-tab extension pings persistent device ID over unencrypted HTTP

The extension makes a random 32-char ID on install, stores it, and sends it over plain HTTP to ping.webstart.page: on install, daily, and on updates, with the extension ID, version, and a channel code.

Anyone on the path can read it.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You install or update the new-tab extension, or a day passes after installation.

No user interaction is needed for the daily ping, the extension fires it automatically.

The extension did this

The extension transmits a persistent device identifier, your extension ID, and version number to ping.webstart.page over plain HTTP.

The request uses HTTP, not HTTPS, so the device identifier and other parameters are visible in cleartext on the network.

02EvidenceFIELD TABLE
Parameters sent in every ping request
FieldValueWhy it matters
Device identifier (mid)
A3F2B1C9D4E07865F1A2B3C4D5E6F708A 32-character random hex ID made on first install, stored permanently, and resent on every ping so the server can track this install.
Extension ID (ex)
kpdnpadaadhikjpaegjbmambpdincpgiThe browser-assigned identifier for the extension, confirming which product is installed.
Extension version (ver)
1.0.0.0The installed version number of the extension.
Distribution channel (ch)
organicA code identifying which marketing channel or bundle the extension was installed from.
Variant / distribution ID (vid)
1A numeric value read from a cookie on defaults.webstart.page at install time, tracking which variant or referral source the user came from.
Event type (s)
1Indicates whether this ping is for a new install (1), daily check-in (2), or extension update (3).
03EvidenceTEMPORAL PATTERN
When this fires
Every 1 day

After the initial install ping, the extension sets a chrome.alarms entry that fires every 1440 minutes (24 hours). Each firing sends the device ID and parameters to ping.webstart.page over HTTP for as long as the extension remains installed.

04EvidenceCODE COMPARE
The code that does this

Machine ID generation and ping dispatch (scripts/ping.js)

What it actually does
// guid() generates a 32-char hex string and persists it as 'machineId'
// in chrome.storage.local. On subsequent calls the stored value is reused,
// so the same ID is sent every time regardless of when the ping fires.

// SendPingDetails is called with:
//   status=1 on install, status=2 on daily alarm, status=3 on update
// The resulting URL uses http:// — no TLS — so mid, ex, ver, and ch
// are transmitted in cleartext over the network.
05EvidenceTHIRD PARTY LIST
Destination receiving the persistent device identifier
  • ping.webstart.page

    Operator analytics endpoint. Receives device ID, extension ID, version, channel, and event type on install, daily, and on each extension update. Connection is over plain HTTP.

  • defaults.webstart.page

    Checked for vid and channel cookies at install time to record the referral source. Cookies are read and then deleted from browser storage.

What it can do

Permissions this extension asks for, as declared in version 1.0.0.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on webstart.page

    https://*.webstart.page/chrome*

  • Read the sites you visit most

    topSites

  • Store data in your browser

    storage

  • Read and change cookies, including the ones that keep you signed in

    cookies

  • Schedule its own background tasks

    alarms

Updated 30 September 2026kpdnpadaadhikjpaegjbmambpdincpgi