Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

ReadFast - Speed Reading

blbpafkooanpdcdcndkcckblghjddpke
Risk Score
4.54
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category ReaderMode
Installs 1,000
Rating 2.9
Last updated 2026-02-21 (4 months ago)
Manifest version MV3
CSP present ❌ no
Developer brillant@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and 3rd-party sharing (+10 privacy pillar).
  • Broad host access (http://*/*, https://*/*) paired with scripting and content_scripts on <all_urls> allows reading/modifying every page visited.
  • clipboardRead permission is not justified by stated RSVP/speed-reading function — silent clipboard access on all sites.
  • Developer uses free Gmail address with no business domain; no verified-publisher status lowers accountability.
  • Low rating (2.9) may reflect user-reported issues; no review red flags detected but rating warrants scrutiny.

Evidence

  • broad_host_access manifest host_permissions include http://*/*, https://*/*; content_scripts match <all_urls> — full cross-site reach.
  • generic_privacy_policy store Privacy URL is myaccount.google.com/privacypolicy — Google account policy, scope_extension=false, data_collection=true, third_party_sharing=true.
  • free_webmail_developer store Developer email brillant@gmail.com; no business domain; domain_age_ct not queried due to free webmail.
  • clipboardRead_mismatch manifest clipboardRead declared but RSVP speed-reading on selected text does not require clipboard access.
  • no_csp crx content_security_policy is null; MV3 provides some default protections but no explicit CSP set.
  • low_rating store Rating 2.9 — below threshold; insufficient rating_count data to apply +1.0 penalty (count unknown).
  • no_code_findings crx code_findings_raw empty; obfuscation_score=0.0; js_external_hosts empty — no malicious code signals detected.
  • recently_updated store last_updated Feb 2026, months_since_update=4; maintenance score low (+1.5).

Permissions Breakdown

  • contextMenus low Adds right-click menu; consistent with RSVP text selection workflow.
  • activeTab low Scoped to user-activated tab; low blast radius.
  • scripting medium Can inject scripts; combined with <all_urls> host access elevates reach.
  • storage low Local preference storage; standard for settings persistence.
  • clipboardRead medium Can read clipboard contents silently; unnecessary for basic RSVP on selected text.
  • http://*/* high Broad host access to all HTTP sites enables content injection anywhere.
  • https://*/* high Broad host access to all HTTPS sites including sensitive domains.
  • <all_urls> (content_scripts) high Content script injected on every page; combines with scripting permission for full-page reach.

Pillar Scores

Permissions5.50
Reputation6.50
Network2.00
Webstore0.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:21
Listing SHA 2a9c4010bc3f…
Force block — not fired
Score recovered no
Elapsed 24.2s