view reddit images directly
ifcbbmfoblmmckaacfoeillbkchclfpe
Risk Score
4.83
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension; data collection and 3rd-party sharing admitted without extension-specific context.
- Brand impersonation: 'reddit' mentioned by unverified gmail developer who is not a confirmed Reddit owner.
- Free-webmail developer (temu.toolkit@gmail.com) with no verified business presence elevates takeover/abuse risk.
- innerHTML DOM-XSS sink in popup.100f6462.js — no CSP present to mitigate; escalated code risk.
- declarativeNetRequest on reddit.com content scripts allows request modification on authenticated sessions.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; developer is gmail account, not verified Reddit owner.
- generic_privacy_policy store Privacy URL points to Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- free_webmail_developer manifest developer_email=temu.toolkit@gmail.com; no business domain; domain_age_ct not queried.
- dom_xss_sink_no_csp crx dom_sink_innerhtml_userctrl in popup.100f6462.js; csp_present=false escalates to +2.0 code quality.
- maintenance_6_12mo store months_since_update=12; last_updated=June 23 2025; maintenance score +3.5.
- no_bad_hosts_or_cves crx bad_host_hits=[], cve_findings_raw=[], affiliate_hits=[], monetization_hits=[] — no network threat intel hits.
- mv3_no_csp manifest MV3 extension; no CSP declared — MV3 has strict default so no +2.0 network penalty applies.
- host_scope_narrow manifest host_permissions scoped to 4 reddit/redd.it subdomains only; matches stated image-viewer function.
Permissions Breakdown
- storage low Local state persistence only; low abuse potential.
- declarativeNetRequest medium Can modify/redirect network requests; scope limited to declared host_permissions.
- *://i.redd.it/* low Reddit image CDN — matches stated function.
- *://external-preview.redd.it/* low Reddit preview CDN — matches stated function.
- *://preview.redd.it/* low Reddit preview CDN — matches stated function.
- *://www.reddit.com/* medium Content script on reddit.com; can read/modify page DOM including login context.
Pillar Scores
Permissions2.00
Reputation7.50
Network2.00
Webstore3.50
Maintenance3.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:42
Listing SHA
e4b1cdfc7eb9…
Force block
— not fired
Score recovered
no
Elapsed
25.1s