Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Fast Reader

diddbodgphcilmabighkdfbakmfonpen
Risk Score
4.26
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category ReaderMode
Installs 266
Rating 4.6
Last updated 2025-08-17 (10 months ago)
Manifest version MV3
CSP present ❌ no
Developer toomanyappsforyou@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — does not describe this extension's data handling at all.
  • install_url_hijack: onInstalled opens third-party URL (speedreaderwelcome.github.io).
  • uninstall_url_hijack flag set; redirects user on removal.
  • Two innerHTML DOM-XSS sinks with no CSP; page content could be weaponized.
  • Free-webmail developer (gmail) with no verified business identity or privacy policy.

Evidence

  • install_url_hijack crx onInstalled opens https://speedreaderwelcome.github.io/ — third-party GitHub Pages site.
  • uninstall_url_hijack crx uninstall_url_hijack==true; target null but flag raised by scanner.
  • generic_privacy_policy store Policy URL is Google account policy; scope_extension==false, data_collection==true, third_party_sharing==true.
  • dom_xss_no_csp crx Two innerHTML sinks in content.js and index.js with csp_present==false — elevated XSS risk.
  • free_webmail_developer store Developer email toomanyappsforyou@gmail.com; no verified publisher, no business domain.
  • js_external_hosts crx Extension references reactjs.org and speedreaderwelcome.github.io as external JS hosts.
  • maintenance store Last updated August 2025; ~10 months — 3–6 month band (+1.5).
  • low_install_count store Only 266 installs; limited blast radius but no community vetting.

Permissions Breakdown

  • contextMenus low Adds right-click menu items; minimal risk.
  • activeTab low Access to current tab only on user gesture; scoped.
  • storage low Local data persistence; no cross-origin risk.
  • scripting medium Can inject scripts into pages; paired with activeTab limits scope.
  • windows low Window management; low standalone risk.

Pillar Scores

Permissions2.30
Reputation6.50
Network0.00
Webstore4.00
Maintenance3.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:27
Listing SHA b08f43d51b8c…
Force block — not fired
Score recovered no
Elapsed 23.8s