Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Reeader - Minimal reader with speed reading

jblbdklppkompnbobkpncbmbjkaeaeah
Risk Score
3.72
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category ReaderMode
Installs 7,000
Rating 4.6
Last updated 2026-05-24 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer 0p0a0r0i@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and 3rd-party sharing.
  • Developer uses numbered-alias Gmail (0p0a0r0i@gmail.com) with no business domain or verified publisher status.
  • new Function() constructor in main.js enables dynamic code execution; no CSP to mitigate.
  • innerHTML DOM sink without CSP creates XSS surface if injected content is attacker-controlled.
  • No host_permissions or content_scripts but scripting+activeTab can still modify active page content.

Evidence

  • privacy_policy_generic store Policy URL is Google's account privacy page; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy (v3.5 rule D).
  • developer_email_free_webmail store Email 0p0a0r0i@gmail.com is free-webmail, no verified business domain; Reputation base penalty applied.
  • function_constructor_found crx code_findings_raw: function_constructor in main.js → +2.5 Code Quality.
  • dom_sink_innerhtml_no_csp crx dom_sink_innerhtml_userctrl + csp_present==false → +2.0 Code Quality (FIX B).
  • no_csp_mv3 manifest MV3 has strict default; no additional Network penalty for missing CSP under v2b.
  • is_featured_by_google store Google Featured badge present; -2.0 Reputation discount applied.
  • no_bad_hosts_no_cves crx threat_intel bad_host_hits empty, cve_findings_raw empty, js_external_hosts empty.
  • recently_updated store months_since_update=1; Maintenance +0.0.

Permissions Breakdown

  • activeTab low Scoped to user-initiated tab; limited blast radius.
  • storage low Local preference storage; no sensitive data access.
  • scripting medium Can inject JS into active tab; combined with activeTab keeps scope narrow.

Pillar Scores

Permissions1.60
Reputation6.50
Network2.00
Webstore0.00
Maintenance0.00
Privacy10.00
Code Quality4.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:44
Listing SHA b777d08e1149…
Force block — not fired
Score recovered no
Elapsed 25.4s