Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Reddit Comment Collapser

njmimaecgocggclbecipdimilidimlpl
Risk Score
3.44
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Productivity
Installs 7,000
Rating 4.8
Last updated 2024-04-22 (26 months ago)
Manifest version MV3
CSP present ❌ no
Developer chromedevstore@tomjwatson.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Extension not updated in 26 months — stale and unpatched against any future vulnerabilities.
  • Brand mention of 'reddit' flagged as impersonation by scanner; developer is not a confirmed Reddit owner.
  • Privacy policy discloses third-party sharing without scoping retention; lacks data-retention clause.
  • No CSP declared (MV3 mitigates partially but content scripts run on reddit.com without explicit policy).
  • developer_domain resolves and appears legitimate (tomjwatson.com), but is_featured badge reduces concern.

Evidence

  • is_featured_by_google store Extension carries Google 'Featured' badge, indicating basic policy compliance review.
  • months_since_update=26 store Last updated April 2024; 26 months stale triggers +8.5 maintenance score.
  • brand_mention.is_impersonation=true store Scanner flagged 'reddit' brand mention; confirmed_owner=false. Developer not verified as Reddit Inc.
  • privacy_policy third_party_sharing=true, retention=false api Policy fetched, scoped to extension, discloses data collection and 3rd-party sharing but no retention clause.
  • no_cve_findings crx No CVEs detected in bundled JS libraries; cve_findings_raw is empty.
  • code_findings_raw empty, obfuscation_score=0.0 crx No suspicious code patterns detected; clean JS scan across 2 files.
  • threat_intel clean api No bad_host_hits, affiliate_hits, or monetization_hits; developer domain resolves and not throwaway.
  • host_permissions narrow manifest Content scripts limited to https://*.reddit.com/*/comments/* — tightly scoped to stated function.

Permissions Breakdown

  • storage low Stores user preferences locally; no data exfiltration risk on its own.
  • https://*.reddit.com/ (host_permission) low Scoped exclusively to reddit.com; matches stated function of collapsing Reddit comments.

Pillar Scores

Permissions0.80
Reputation5.00
Network0.00
Webstore0.00
Maintenance8.50
Privacy2.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:59
Listing SHA ce7300990468…
Force block — not fired
Score recovered no
Elapsed 19.0s