Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Old Reddit Redirect

dneaehbmnbhcippjikoajpoabadpodje
Risk Score
2.26
Risk Level: Low
Recommendation: ✅ ALLOW
Category Productivity
Installs 100,000
Rating 4.7
Last updated 2026-03-08 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer chromedevstore@tomjwatson.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • declarativeNetRequestWithHostAccess can redirect/block reddit.com requests — matches stated purpose but is a high-impact permission.
  • brand_mention flags Reddit impersonation; developer is not confirmed as Reddit's owner.
  • Privacy policy discloses data_collection and third_party_sharing without retention details.
  • Review red-flags match 'redirect' — likely benign (extension's stated function) but noted.
  • No CSP present (MV3 mitigates this but js_file_count=0 means no code surface observed).

Evidence

  • declarativeNetRequestWithHostAccess + reddit host_permissions manifest Intercept/redirect permission scoped to 7 reddit.com subdomains; consistent with stated redirect function.
  • brand_mention.is_impersonation=true store Extension mentions Reddit brand; confirmed_owner=false. Featured by Google partially mitigates impersonation risk.
  • is_featured_by_google=true store Google Featured badge present; -2.0 reputation discount applied.
  • privacy_policy data_collection+third_party_sharing=true, retention=false api Policy scoped to extension, admits data collection and third-party sharing but lacks retention disclosure.
  • code_findings_raw empty, js_file_count=0, obfuscation_score=0.0 crx No JS files detected; no code findings; no obfuscation. Clean code surface.
  • threat_intel all clear api No bad_host_hits, affiliate_hits, monetization_hits. Developer domain resolves, not throwaway.
  • review_red_flags match_count=1 ('redirect') store Single 'redirect' review match — aligns with extension's core function, not malicious indicator.
  • months_since_update=3 store Recently updated March 2026; maintenance risk minimal.

Permissions Breakdown

  • declarativeNetRequestWithHostAccess high Can intercept and redirect network requests; scoped only to reddit.com subdomains, matching stated function.
  • *://reddit.com/* (host) medium Host access to reddit.com family; narrow and consistent with redirect purpose.

Pillar Scores

Permissions3.50
Reputation4.50
Network0.00
Webstore2.00
Maintenance0.00
Privacy2.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:28
Listing SHA a0e52fc68a7a…
Force block — not fired
Score recovered no
Elapsed 20.8s