Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Reddit Promoted Ad Blocker

mmnhjecbajmgkapcinkhdnjabclcnfpg
Risk Score
5.40
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Adblock
Installs 20,000
Rating 4.9
Last updated
Manifest version MV3
CSP present ❌ no
Developer mockerydev@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: 'Reddit' in name by unverified gmail developer, not confirmed owner.
  • Privacy policy is Google's generic account policy — not scoped to this extension at all, admits data collection and 3rd-party sharing.
  • No last_updated date available; maintenance posture is completely unknown.
  • Description promises ad-blocking but extension lacks declarativeNetRequest/webRequest — functional mismatch.
  • Free-webmail developer (gmail) with no verified business identity behind a high-rating product.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true, brands=['reddit'], confirmed_owner=false, dev domain=gmail.com
  • generic_privacy_policy store Policy is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy
  • description_permission_mismatch manifest Promises ad-blocking but no declarativeNetRequest or webRequest declared.
  • maintenance_unknown store last_updated and months_since_update both null; cannot verify currency → scored as >36mo.
  • free_webmail_developer store Developer email mockerydev@gmail.com; no business website; verified_publisher=false.
  • featured_by_google store is_featured_by_google=true; applies -2.0 reputation discount but does not offset impersonation floor.
  • no_csp manifest content_security_policy=null, MV3 (strict default applies, no MV2 penalty).
  • host_permissions_scoped manifest Host permissions limited to reddit.com and old.reddit.com only; no broad host access.

Permissions Breakdown

  • *://www.reddit.com/* medium Host permission scoped to reddit.com only; content script can read/modify reddit pages.
  • *://old.reddit.com/* medium Host permission scoped to old.reddit.com; same content-script access as above.

Pillar Scores

Permissions1.50
Reputation7.50
Network0.00
Webstore4.00
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:56
Listing SHA 7f4d6bca62dd…
Force block — not fired
Score recovered no
Elapsed 32.6s