Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Display Reddit images natively in browser

imiakeaigofbcfdjajmgjfnohjlekndg
Risk Score
3.53
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Other
Installs 6,000
Rating 4.8
Last updated 2026-04-06 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer chromeexts@jonathankay.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — scope_extension=false, data_collection=true, third_party_sharing=true; no extension-specific disclosure.
  • Brand impersonation flag: 'reddit' mentioned, confirmed_owner=false; extension modifies Reddit CDN requests.
  • No content security policy (MV3 default enforcement present but no explicit CSP declared); low JS surface mitigates.
  • declarativeNetRequest can alter Accept headers on Reddit image hosts; minimal but non-zero capability.
  • Developer identity unverifiable via CT logs (crt.sh error); domain resolves but cert history unavailable.

Evidence

  • privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true — triggers v3.5(D) +10.0 privacy.
  • brand_impersonation store brand_mention.is_impersonation=true, brands=['reddit'], confirmed_owner=false, not verified/featured → +2.0 reputation.
  • host_permissions_narrow manifest 5 host_permissions all scoped to *.redd.it / www.reddit.com/media — matches stated function; justified discount applied.
  • no_code_findings crx js_file_count=0, code_findings_raw=[], obfuscation_score=0.0 — no JS surface scanned.
  • no_cve_findings crx cve_findings_raw=[] — no library CVEs detected.
  • recently_updated store months_since_update=2 → maintenance score 0.0.
  • no_bad_host_hits api threat_intel bad_host_hits=[], affiliate_hits=[], monetization_hits=[] — clean threat intel.
  • domain_ct_unavailable api domain_age_ct.queried=false due to crt.sh HTTPError; cannot confirm cert history for jonathankay.com.

Permissions Breakdown

  • declarativeNetRequest medium Can modify HTTP headers/requests; scoped to 5 Reddit image CDN hosts, low abuse potential here.
  • *://i.redd.it/* low Narrow Reddit image CDN host; matches stated function.
  • *://preview.redd.it/* low Narrow Reddit preview CDN host; matches stated function.
  • *://cf.preview.redd.it/* low Narrow Cloudflare Reddit preview host; matches stated function.
  • *://external-preview.redd.it/* low Narrow Reddit external preview host; matches stated function.
  • *://www.reddit.com/media* low Narrow Reddit media path; matches stated function.

Pillar Scores

Permissions1.30
Reputation6.00
Network0.00
Webstore2.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:44
Listing SHA a1f15c25fa20…
Force block — not fired
Score recovered no
Elapsed 22.3s