Brentford Football Club

Brentford Football Club

ID: nhgihpciiooacimlepldjbfkkpejmlfi

Extension Info & Metadata

Status
Active
Version
3.2.1
Size
2.92 MB
Rating
5.0/5
Reviews
4
Users
76
Type
Extension
Updated
Jun 12, 2026
Category
Tools
Price
Free
Featured
No
Visibility
Listed
Mature
No
By Google
No
Trusted
Yes

Publisher Contextual Analysis

Trusted
Author
brandTURBOView Profile
Country
DE
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
Yes
Mailbox exists
Yes
Address
Straßburger Str. 55 Berlin 10405 DE
Website
Visit
Total Extensions
99
Active
53
Obsolete
46
Listed
37
Unlisted
62
Total Users
29,056
Screenshot 1
Screenshot 2
Screenshot 3

Official Brentford Football Club new tab. Read and watch the latest news, highlights and interviews.

With your new homepage you can create your own personal space by customising our favourite wallpapers, arrange your favourite websites and make every new tab an interactive experience with exclusive content. Customise your favourite browser and stay update with the latest news about players, social media, trends, tickets and other exclusive content. Join our amazing community and make your own BFC new tab.

Item
Type
Severity
Description
topSites
Permission
High
This permission accesses the list of most visited websites. Rated High because it can reveal browsing patterns, identify frequently accessed service, and gather user behavior data.
Contextual Risk Factors
Risk Factor
High
The following context increases the overall risk:• 15% increase: Older manifest version lacks modern security controls
Older Manifest Version
Risk Factor
Medium
This extension uses Manifest Version 2

The extension silently POSTs a per-installation user hash and an engagement score to a Google Cloud Function hosted under searchturbo-com — a domain belonging to the publisher's sister product 'SearchTurbo', not to brandturbo.vip or Brentford FC. The CWS listing declares zero data collection categories, making this an undisclosed transmission of user-identifying behavioral data to a third-party endpoint.

background.js (Line 913)
var D, F = "https://m.instantsearch.net/stats";localStorage.firstRun || (localStorage.firstRun = Date.now());var C = parseInt(localStorage.firstRun);var N = function(t, e) {  var r = D.getState().config.data;  fetch("".concat("https://europe-west1-api-searchturbo-com.cloudfunctions.net/invite-function/api",    "/scores"), {    method: "POST",    headers: {      "Content-Type": "application/json"    },    body: JSON.stringify({      hash: t,      score: e,      rtag: r.rtag    })  })};

Every time the news panel is rendered, the extension contacts Jeeng (a push-notification ad-monetization platform) at azurewebsites.net with a hardcoded domain_id and user_id. Jeeng is entirely unrelated to Brentford FC or a new-tab reading experience; its presence indicates the extension's real purpose is monetizing its user base through undisclosed ad delivery, consistent with the publisher's known pattern of wrapping monetization SDKs in sports-club branding.

698.js (Line 360)
(0, s.useEffect)((function() {  O(i, c.rtag, d), b || function(e) {    e({      name: "ads",      url: "https://jeeng-server.azurewebsites.net/api/push-monetization?domain_id=3AJmqgQdl1&user_id=bfd230b1-7688-43a4-bb68-ce1a5ff305d2&count=5"    })  }(i)}), [c.rtag, h]);

On every tracked user interaction, an analytics beacon is dispatched to `https://m.instantsearch.net/stats` carrying event type, event value, rtag identifier, source flag 'e', JS version and time-since-install. This domain is not the publisher's declared domain (brandturbo.vip), and the CWS data-collection disclosure is empty — this constitutes undisclosed behavioral tracking sent to a third-party infrastructure domain.

background.js (Line 991)
t.async ? function(t, e) {  var r = arguments.length > 2 && void 0 !== arguments[2] ? arguments[2] : function() {};  navigator.sendBeacon ? r(navigator.sendBeacon(t, JSON.stringify(e))) : r(!1)}(F, i, t.status) : M(F, i, t.status);

By severity

Critical0
High2
Medium1
Low0

Versions scanned

Showing 1 of 2 scanned versions with more than one unique finding. Counts are unique findings that include each version.

Extension VersionCode Review Findings
3.2.13

Files with findings

2 distinct paths — top paths by unique finding count:

  • background.js2
  • 698.js1
S.No.
Category
Severity
File
Summary
Found in Version
1Unauthorized Data Collection
high
background.js (line 913)The extension silently POSTs a per-installation user hash and an engagement score to a Google Cloud Function hosted under searchturbo-com — a domain belonging to the publisher's sister product 'SearchTurbo', not to br…
2Unauthorized Data Collection
high
698.js (line 360)Every time the news panel is rendered, the extension contacts Jeeng (a push-notification ad-monetization platform) at azurewebsites.net with a hardcoded domain_id and user_id. Jeeng is entirely unrelated to Brentford …
3Tracking
medium
background.js (line 991)On every tracked user interaction, an analytics beacon is dispatched to `https://m.instantsearch.net/stats` carrying event type, event value, rtag identifier, source flag 'e', JS version and time-since-install. This d…
URLs
109
IPv4
13
IPv6
0

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

Gain full insight into all external connections.

Upgrade for full visibility.

www.w3.org/1999/02/22-rdf-syntax-nshttp://www.w3.org/1999/02/22-rdf-syntax-ns#
ns.adobe.com/xap/1.0/http://ns.adobe.com/xap/1.0/
ns.adobe.com/xap/1.0/mm/http://ns.adobe.com/xap/1.0/mm/
ns.adobe.com/xap/1.0/sType/ResourceRefhttp://ns.adobe.com/xap/1.0/sType/ResourceRef#
palantir.com/http://palantir.com/Palantirhttp://palantir.com/http://palantir.com/Palantir
chrome.google.com/webstore/detail/startpage/https://chrome.google.com/webstore/detail/startpage/
www.brandturbo.vip-https://www.brandturbo.vip/
www.brandturbo.vip/privacyhttps://www.brandturbo.vip/privacy
www.brandturbo.vip/termshttps://www.brandturbo.vip/terms
www.brandturbo.vip/.netlify/functions/feedbackhttps://www.brandturbo.vip/.netlify/functions/feedback
Showing 1 to 10 of 110 rows
Rows per page:

Gain full insight into all external connections.

Upgrade for full visibility.

1.22.17.37
IPv4
-
18.18.43.29
IPv4
-
28.11.53.29
IPv4
-
18.19.43.3
IPv4
-
17.14.37.23
IPv4
-
31.1.59.16
IPv4
-
28.22.59.5
IPv4
-
17.18.42.29
IPv4
-
24.1.46.24
IPv4
-
19.22.45.37
IPv4
-
17.12.36.21
IPv4
-
39.12.73.2
IPv4
-
35.28.72.62
IPv4
-
Showing 1 to 13 of 20 rows
Rows per page:
Version
Size
Is Malicious
Findings
Permhash
4.1.1
Latest
2.92 MB
Malicious
3.2.1
2.96 MB
Malicious
3
Showing 1 to 2 of 10 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files (scanned top 25 shared text files)

No comparable text files found between these versions.

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.