Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

view reddit images directly

ifcbbmfoblmmckaacfoeillbkchclfpe
Risk Score
4.83
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 7,000
Rating 4.5
Last updated 2025-06-23 (12 months ago)
Manifest version MV3
CSP present ❌ no
Developer temu.toolkit@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension; data collection and 3rd-party sharing admitted without extension-specific context.
  • Brand impersonation: 'reddit' mentioned by unverified gmail developer who is not a confirmed Reddit owner.
  • Free-webmail developer (temu.toolkit@gmail.com) with no verified business presence elevates takeover/abuse risk.
  • innerHTML DOM-XSS sink in popup.100f6462.js — no CSP present to mitigate; escalated code risk.
  • declarativeNetRequest on reddit.com content scripts allows request modification on authenticated sessions.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; developer is gmail account, not verified Reddit owner.
  • generic_privacy_policy store Privacy URL points to Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • free_webmail_developer manifest developer_email=temu.toolkit@gmail.com; no business domain; domain_age_ct not queried.
  • dom_xss_sink_no_csp crx dom_sink_innerhtml_userctrl in popup.100f6462.js; csp_present=false escalates to +2.0 code quality.
  • maintenance_6_12mo store months_since_update=12; last_updated=June 23 2025; maintenance score +3.5.
  • no_bad_hosts_or_cves crx bad_host_hits=[], cve_findings_raw=[], affiliate_hits=[], monetization_hits=[] — no network threat intel hits.
  • mv3_no_csp manifest MV3 extension; no CSP declared — MV3 has strict default so no +2.0 network penalty applies.
  • host_scope_narrow manifest host_permissions scoped to 4 reddit/redd.it subdomains only; matches stated image-viewer function.

Permissions Breakdown

  • storage low Local state persistence only; low abuse potential.
  • declarativeNetRequest medium Can modify/redirect network requests; scope limited to declared host_permissions.
  • *://i.redd.it/* low Reddit image CDN — matches stated function.
  • *://external-preview.redd.it/* low Reddit preview CDN — matches stated function.
  • *://preview.redd.it/* low Reddit preview CDN — matches stated function.
  • *://www.reddit.com/* medium Content script on reddit.com; can read/modify page DOM including login context.

Pillar Scores

Permissions2.00
Reputation7.50
Network2.00
Webstore3.50
Maintenance3.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:42
Listing SHA e4b1cdfc7eb9…
Force block — not fired
Score recovered no
Elapsed 25.1s