Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Reddit Enhancement Suite

kbmfpngjjgdllneeigpgjifpgocmfgmb
Risk Score
4.21
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 1,000,000
Rating 4.7
Last updated 2025-01-24 (17 months ago)
Manifest version MV3
CSP present ✅ yes
Developer reddit-enhancement-suite-devs@googlegroups.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • brand_mention flags 'reddit' as impersonation but extension is well-known RES project; confirmed_owner==false inflates Reputation score.
  • Privacy policy fetched but scope_extension==false and retention not disclosed; data handling unclear for 1M users.
  • webRequest permission on *.reddit.com combined with scripting creates meaningful read/intercept capability.
  • months_since_update==17 crosses 6-month stale threshold; no changelog evidence to reduce maintenance risk.
  • innerHTML sinks (dom_sink_innerhtml_userctrl) in two entry files; DOMPurify bundled but sink pattern still present.

Evidence

  • verified_publisher+featured store Extension is verified publisher AND featured by Google; strong legitimacy signal.
  • brand_mention_impersonation api brand_mention.is_impersonation=true, confirmed_owner=false, but RES is a well-known open-source project.
  • privacy_policy_scope_gap api Policy fetched, data_collection=false, scope_extension=false, retention=false, third_party_silence=true.
  • dom_xss_sinks crx Two innerHTML-from-variable sinks in options.entry.js and foreground.entry.js; DOMPurify also bundled.
  • maintenance_stale store months_since_update=17; falls in 12-24mo band (+6.0 base), MV3 so no triple-stale CVE amplifier.
  • webRequest_high_perm manifest webRequest on https://*.reddit.com/* allows observation of all Reddit network traffic.
  • no_bad_hosts_no_affiliate api threat_intel: bad_host_hits=[], affiliate_hits=[], monetization_hits=[]; only time.akamai.com external.
  • csp_present_mv3 manifest Strict CSP present: script-src 'self'; connect-src https:; no unsafe-eval/inline. MV3 default enforced.

Permissions Breakdown

  • tabs medium Can read tab URLs and metadata; medium risk for a site-specific extension.
  • history medium Access to full browsing history; elevated but scoped to Reddit feature use.
  • storage low Stores user preferences locally; standard for enhancement suites.
  • unlimitedStorage low Allows large local cache; no exfil risk by itself.
  • webRequest high Can observe all network requests on permitted hosts; significant capability.
  • scripting medium Can inject scripts into pages; scoped to *.reddit.com/* host permission.
  • https://*.reddit.com/* medium Host access narrowly scoped to Reddit only; mitigates broad-access risk.

Pillar Scores

Permissions4.30
Reputation4.00
Network2.00
Webstore2.50
Maintenance6.00
Privacy9.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:47
Listing SHA 738ebd7f3e61…
Force block — not fired
Score recovered no
Elapsed 27.6s