Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Reddit Enhancer

onglbklimdjicpdadjieknodkkmjldoa
Risk Score
4.37
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 20,000
Rating 4.4
Last updated 2026-05-17 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer joelacus.dev@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and third-party sharing.
  • Brand impersonation: 'Reddit' mentioned in name/description, developer is unverified gmail user, not Reddit Inc.
  • Install-URL hijack: onInstalled opens 'restore_config.html?&lang=' — unusual onboarding redirect.
  • Free-webmail developer (gmail) with no verified business domain; low accountability.
  • new Function() constructor present in minified bundle; no CSP to restrict dynamic code execution.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; confirmed_owner=false; developer_domain=gmail.com; brands=['reddit'].
  • install_url_hijack crx install_url_hijack=true; target='restore_config.html?&lang=' — onInstalled redirect to internal page with query params.
  • generic_privacy_policy store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • free_webmail_developer store Developer email joelacus.dev@gmail.com; no verified publisher; no business domain.
  • function_constructor crx new Function() found in popup.js and restore_config.js; no CSP present to restrict dynamic execution.
  • no_csp manifest content_security_policy=null on MV3; v2 fix (b) not applicable but dynamic code risk elevated.
  • is_featured_by_google store Extension carries Featured badge; partial reputation mitigation applied.
  • host_permissions_scoped manifest Host access limited to *.reddit.com/* and *.redd.it/*; no broad <all_urls>.

Permissions Breakdown

  • storage low Stores user preferences locally; low risk.
  • tabs medium Can read tab URLs/titles; moderate risk.
  • declarativeNetRequest medium Can block/redirect network requests without seeing content.
  • contextMenus low Adds items to right-click menu; minimal risk.
  • *://*.reddit.com/* medium Scoped host access to Reddit only; narrows blast radius.
  • *://*.redd.it/* medium Scoped host access to Reddit CDN domain; low concern.

Pillar Scores

Permissions2.30
Reputation7.00
Network0.00
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:02
Listing SHA 84e75de0b7c4…
Force block — not fired
Score recovered no
Elapsed 24.0s