Reddit Enhancement Suite
kbmfpngjjgdllneeigpgjifpgocmfgmb
Risk Score
4.21
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- brand_mention flags 'reddit' as impersonation but extension is well-known RES project; confirmed_owner==false inflates Reputation score.
- Privacy policy fetched but scope_extension==false and retention not disclosed; data handling unclear for 1M users.
- webRequest permission on *.reddit.com combined with scripting creates meaningful read/intercept capability.
- months_since_update==17 crosses 6-month stale threshold; no changelog evidence to reduce maintenance risk.
- innerHTML sinks (dom_sink_innerhtml_userctrl) in two entry files; DOMPurify bundled but sink pattern still present.
Evidence
- verified_publisher+featured store Extension is verified publisher AND featured by Google; strong legitimacy signal.
- brand_mention_impersonation api brand_mention.is_impersonation=true, confirmed_owner=false, but RES is a well-known open-source project.
- privacy_policy_scope_gap api Policy fetched, data_collection=false, scope_extension=false, retention=false, third_party_silence=true.
- dom_xss_sinks crx Two innerHTML-from-variable sinks in options.entry.js and foreground.entry.js; DOMPurify also bundled.
- maintenance_stale store months_since_update=17; falls in 12-24mo band (+6.0 base), MV3 so no triple-stale CVE amplifier.
- webRequest_high_perm manifest webRequest on https://*.reddit.com/* allows observation of all Reddit network traffic.
- no_bad_hosts_no_affiliate api threat_intel: bad_host_hits=[], affiliate_hits=[], monetization_hits=[]; only time.akamai.com external.
- csp_present_mv3 manifest Strict CSP present: script-src 'self'; connect-src https:; no unsafe-eval/inline. MV3 default enforced.
Permissions Breakdown
- tabs medium Can read tab URLs and metadata; medium risk for a site-specific extension.
- history medium Access to full browsing history; elevated but scoped to Reddit feature use.
- storage low Stores user preferences locally; standard for enhancement suites.
- unlimitedStorage low Allows large local cache; no exfil risk by itself.
- webRequest high Can observe all network requests on permitted hosts; significant capability.
- scripting medium Can inject scripts into pages; scoped to *.reddit.com/* host permission.
- https://*.reddit.com/* medium Host access narrowly scoped to Reddit only; mitigates broad-access risk.
Pillar Scores
Permissions4.30
Reputation4.00
Network2.00
Webstore2.50
Maintenance6.00
Privacy9.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:47
Listing SHA
738ebd7f3e61…
Force block
— not fired
Score recovered
no
Elapsed
27.6s