Display Reddit images natively in browser
imiakeaigofbcfdjajmgjfnohjlekndg
Risk Score
3.53
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy is Google's generic account policy — scope_extension=false, data_collection=true, third_party_sharing=true; no extension-specific disclosure.
- Brand impersonation flag: 'reddit' mentioned, confirmed_owner=false; extension modifies Reddit CDN requests.
- No content security policy (MV3 default enforcement present but no explicit CSP declared); low JS surface mitigates.
- declarativeNetRequest can alter Accept headers on Reddit image hosts; minimal but non-zero capability.
- Developer identity unverifiable via CT logs (crt.sh error); domain resolves but cert history unavailable.
Evidence
- privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true — triggers v3.5(D) +10.0 privacy.
- brand_impersonation store brand_mention.is_impersonation=true, brands=['reddit'], confirmed_owner=false, not verified/featured → +2.0 reputation.
- host_permissions_narrow manifest 5 host_permissions all scoped to *.redd.it / www.reddit.com/media — matches stated function; justified discount applied.
- no_code_findings crx js_file_count=0, code_findings_raw=[], obfuscation_score=0.0 — no JS surface scanned.
- no_cve_findings crx cve_findings_raw=[] — no library CVEs detected.
- recently_updated store months_since_update=2 → maintenance score 0.0.
- no_bad_host_hits api threat_intel bad_host_hits=[], affiliate_hits=[], monetization_hits=[] — clean threat intel.
- domain_ct_unavailable api domain_age_ct.queried=false due to crt.sh HTTPError; cannot confirm cert history for jonathankay.com.
Permissions Breakdown
- declarativeNetRequest medium Can modify HTTP headers/requests; scoped to 5 Reddit image CDN hosts, low abuse potential here.
- *://i.redd.it/* low Narrow Reddit image CDN host; matches stated function.
- *://preview.redd.it/* low Narrow Reddit preview CDN host; matches stated function.
- *://cf.preview.redd.it/* low Narrow Cloudflare Reddit preview host; matches stated function.
- *://external-preview.redd.it/* low Narrow Reddit external preview host; matches stated function.
- *://www.reddit.com/media* low Narrow Reddit media path; matches stated function.
Pillar Scores
Permissions1.30
Reputation6.00
Network0.00
Webstore2.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:44
Listing SHA
a1f15c25fa20…
Force block
— not fired
Score recovered
no
Elapsed
22.3s