ReadFast - Speed Reading
blbpafkooanpdcdcndkcckblghjddpke
Risk Score
4.54
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and 3rd-party sharing (+10 privacy pillar).
- Broad host access (http://*/*, https://*/*) paired with scripting and content_scripts on <all_urls> allows reading/modifying every page visited.
- clipboardRead permission is not justified by stated RSVP/speed-reading function — silent clipboard access on all sites.
- Developer uses free Gmail address with no business domain; no verified-publisher status lowers accountability.
- Low rating (2.9) may reflect user-reported issues; no review red flags detected but rating warrants scrutiny.
Evidence
- broad_host_access manifest host_permissions include http://*/*, https://*/*; content_scripts match <all_urls> — full cross-site reach.
- generic_privacy_policy store Privacy URL is myaccount.google.com/privacypolicy — Google account policy, scope_extension=false, data_collection=true, third_party_sharing=true.
- free_webmail_developer store Developer email brillant@gmail.com; no business domain; domain_age_ct not queried due to free webmail.
- clipboardRead_mismatch manifest clipboardRead declared but RSVP speed-reading on selected text does not require clipboard access.
- no_csp crx content_security_policy is null; MV3 provides some default protections but no explicit CSP set.
- low_rating store Rating 2.9 — below threshold; insufficient rating_count data to apply +1.0 penalty (count unknown).
- no_code_findings crx code_findings_raw empty; obfuscation_score=0.0; js_external_hosts empty — no malicious code signals detected.
- recently_updated store last_updated Feb 2026, months_since_update=4; maintenance score low (+1.5).
Permissions Breakdown
- contextMenus low Adds right-click menu; consistent with RSVP text selection workflow.
- activeTab low Scoped to user-activated tab; low blast radius.
- scripting medium Can inject scripts; combined with <all_urls> host access elevates reach.
- storage low Local preference storage; standard for settings persistence.
- clipboardRead medium Can read clipboard contents silently; unnecessary for basic RSVP on selected text.
- http://*/* high Broad host access to all HTTP sites enables content injection anywhere.
- https://*/* high Broad host access to all HTTPS sites including sensitive domains.
- <all_urls> (content_scripts) high Content script injected on every page; combines with scripting permission for full-page reach.
Pillar Scores
Permissions5.50
Reputation6.50
Network2.00
Webstore0.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:21
Listing SHA
2a9c4010bc3f…
Force block
— not fired
Score recovered
no
Elapsed
24.2s