Fast Reader
diddbodgphcilmabighkdfbakmfonpen
Risk Score
4.26
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — does not describe this extension's data handling at all.
- install_url_hijack: onInstalled opens third-party URL (speedreaderwelcome.github.io).
- uninstall_url_hijack flag set; redirects user on removal.
- Two innerHTML DOM-XSS sinks with no CSP; page content could be weaponized.
- Free-webmail developer (gmail) with no verified business identity or privacy policy.
Evidence
- install_url_hijack crx onInstalled opens https://speedreaderwelcome.github.io/ — third-party GitHub Pages site.
- uninstall_url_hijack crx uninstall_url_hijack==true; target null but flag raised by scanner.
- generic_privacy_policy store Policy URL is Google account policy; scope_extension==false, data_collection==true, third_party_sharing==true.
- dom_xss_no_csp crx Two innerHTML sinks in content.js and index.js with csp_present==false — elevated XSS risk.
- free_webmail_developer store Developer email toomanyappsforyou@gmail.com; no verified publisher, no business domain.
- js_external_hosts crx Extension references reactjs.org and speedreaderwelcome.github.io as external JS hosts.
- maintenance store Last updated August 2025; ~10 months — 3–6 month band (+1.5).
- low_install_count store Only 266 installs; limited blast radius but no community vetting.
Permissions Breakdown
- contextMenus low Adds right-click menu items; minimal risk.
- activeTab low Access to current tab only on user gesture; scoped.
- storage low Local data persistence; no cross-origin risk.
- scripting medium Can inject scripts into pages; paired with activeTab limits scope.
- windows low Window management; low standalone risk.
Pillar Scores
Permissions2.30
Reputation6.50
Network0.00
Webstore4.00
Maintenance3.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:27
Listing SHA
b08f43d51b8c…
Force block
— not fired
Score recovered
no
Elapsed
23.8s