Readl Reader mode

ID: dppnhoaonckcimpejpjodcdoenfjleme

Could be malicious

Supported Languages

๐Ÿ‡ง๐Ÿ‡ฉBengali
๐Ÿ‡ง๐Ÿ‡ทBrazilian Portuguese
๐Ÿ‡ฌ๐Ÿ‡งBritish English
๐Ÿ‡ง๐Ÿ‡ฌBulgarian
๐Ÿ‡ช๐Ÿ‡ธCatalan
๐Ÿ‡จ๐Ÿ‡ณChinese (Simplified)
๐Ÿ‡น๐Ÿ‡ผChinese (Traditional)
๐Ÿ‡ญ๐Ÿ‡ทCroatian
๐Ÿ‡จ๐Ÿ‡ฟCzech
๐Ÿ‡ฉ๐Ÿ‡ฐDanish
๐Ÿ‡ณ๐Ÿ‡ฑDutch
๐Ÿ‡บ๐Ÿ‡ธEnglish
๐Ÿ‡ช๐Ÿ‡ชEstonian
๐Ÿ‡ต๐Ÿ‡ญFilipino
๐Ÿ‡ซ๐Ÿ‡ฎFinnish
๐Ÿ‡ซ๐Ÿ‡ทFrench
๐Ÿ‡ฉ๐Ÿ‡ชGerman
๐Ÿ‡ฌ๐Ÿ‡ทGreek
๐Ÿ‡ฎ๐Ÿ‡ณGujarati
๐Ÿ‡ฎ๐Ÿ‡ณHindi
๐Ÿ‡ญ๐Ÿ‡บHungarian
๐Ÿ‡ฎ๐Ÿ‡ฉIndonesian
๐Ÿ‡ฎ๐Ÿ‡นItalian
๐Ÿ‡ฏ๐Ÿ‡ตJapanese
๐Ÿ‡ฐ๐Ÿ‡ทKorean
๐Ÿ‡ฒ๐Ÿ‡ฝLatin American Spanish
๐Ÿ‡ฑ๐Ÿ‡ปLatvian
๐Ÿ‡ฑ๐Ÿ‡นLithuanian
๐Ÿ‡ฒ๐Ÿ‡พMalay
๐Ÿ‡ฎ๐Ÿ‡ณMalayalam
๐Ÿ‡ฎ๐Ÿ‡ณMarathi
๐Ÿ‡ณ๐Ÿ‡ดNorwegian
๐Ÿ‡ต๐Ÿ‡ฑPolish
๐Ÿ‡ต๐Ÿ‡นPortuguese
๐Ÿ‡ท๐Ÿ‡ดRomanian
๐Ÿ‡ท๐Ÿ‡บRussian
๐Ÿ‡ท๐Ÿ‡ธSerbian
๐Ÿ‡ธ๐Ÿ‡ฐSlovak
๐Ÿ‡ธ๐Ÿ‡ฎSlovenian
๐Ÿ‡ช๐Ÿ‡ธSpanish
๐Ÿ‡ธ๐Ÿ‡ชSwedish
๐Ÿ‡ฎ๐Ÿ‡ณTamil
๐Ÿ‡ฎ๐Ÿ‡ณTelugu
๐Ÿ‡น๐Ÿ‡ญThai
๐Ÿ‡น๐Ÿ‡ทTurkish
๐Ÿ‡บ๐Ÿ‡ฆUkrainian
๐Ÿ‡บ๐Ÿ‡ธUS English
๐Ÿ‡ป๐Ÿ‡ณVietnamese

Extension Info & Metadata

Status
Removed
Version
1.1.8
Size
0.12 MB
Rating
4.6/5
Reviews
14
Users
1,867,009
Type
Extension
Updated
Aug 3, 2022
Category
7_productivity
Price
Free
Featured
No
Visibility
Listed
Mature
No
By Google
No
Trusted
Yes

Publisher Contextual Analysis

Trusted
Author
hungdower363View Profile
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Total Extensions
1
Active
0
Obsolete
1
Listed
1
Unlisted
0
Total Users
1,867,009

Read web pages without ads, banners, images and other distractions in reader mode and ease your gaze.

Readl Reader Mode is a helpful extension that allows you to read articles without banners, ads, background noise, etc. The main features of this app are: โœ” Reader Mode - Easier perception of information โœ” Customizable fonts, themes, sizes โœ” No ads, navigation, banner on the screen โœ” Shows pictures This app will open any article in a simple and clutter-free environment.

Item
Type
Severity
Description
<all_urls>
Permission
Critical
This permission grants access to all websites without restriction. Rated High because it can access any web content, monitor all web activity, and potentially steal sensitive data across all sites.
Contextual Risk Factors
Risk Factor
High
The following context increases the overall risk:โ€ข 15% increase: Older manifest version lacks modern security controls
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
declarativeContent
Permission
Medium
This permission controls extension activation based on page content. Rated Medium because it can monitor page content matches and selectively activate extension features.
Older Manifest Version
Risk Factor
Medium
This extension uses Manifest Version 2
contextMenus
Permission
Low
This permission adds items to browser context menus. Rated Medium because it only modifies right-click menus without access to page content.
chrome://favicon/
Permission
Unknown
No classification available for this permission.

The background page implements Google Analytics tracking (UA-211039558-1) with `ga('set','checkProtocolTask',null)` โ€” a well-known technique to disable GA's built-in protocol validation check, which normally prevents GA from firing on non-HTTP protocols like `chrome-extension://`. This intentional bypass allows covert analytics collection within the extension context. A pageview hit is fired on every browser session start, reporting extension usage back to a third-party analytics endpoint without any user disclosure.

background.js (Line 3)
window.ga = window.ga || function() {    (ga.q = ga.q || []).push(arguments)  }, ga.l = +new Date, ga("create", "UA-211039558-1", "auto"), ga("set", "checkProtocolTask", null), ga("send", {    hitType: "pageview",    page: "/background"  }),  function() {    const e = document.createElement("script");    e.type = "text/javascript", e.async = !0, e.src = "https://www.google-analytics.com/analytics.js";    const t = document.getElementsByTagName("script")[0];    t.parentNode.insertBefore(e, t)  }();

Full page URLs are stored as keys in `chrome.storage.sync` (values 0/1 to toggle reader mode). Because `chrome.storage.sync` is backed by Google Sync servers, every URL the user opens in reader mode is transmitted to and persisted on Google's infrastructure. Combined with `content.js` running on every page load to query these same sync keys, the extension effectively builds and remotely stores a browsable URL history without explicit user disclosure that this data leaves the device.

background.js (Line 2)
"open-reader" === e.cmd && e.article ? (chrome.storage.sync.set({    [t.tab.url]: 1  }), cache[t.tab.id] = e.article, cache[t.tab.id].url = o, chrome.tabs.update(r, {    url: chrome.runtime.getURL("reader/index.html?id=" + r)  }))...  // and later when closing:  var n = String(e.favIconUrl).replace("chrome://favicon/", "");chrome.storage.sync.set({  [n]: 0})

This content script runs on every page the user visits (matches `<all_urls>`, all frames) and calls `chrome.storage.sync.get` with the current page's full URL as the lookup key on every single page load. While the stated purpose is to auto-enable reader view, this pattern means a network round-trip to Google Sync occurs for every URL the user navigates to, allowing Google to observe browsing patterns through sync access logs. The all-frames injection also means iframes within pages trigger this lookup.

content.js (Line 1)
chrome.storage.sync.get([window.location.href], (function(e) {  1 == e[window.location.href] && chrome.runtime.sendMessage({    type: "enable"  })}));

The reader view page loads CSS and font resources directly from three external CDN domains (cdnjs.cloudflare.com, stackpath.bootstrapcdn.com, fonts.googleapis.com). Each of these requests reveals the user's IP address and that they are using this extension to external parties. The manifest's `content_security_policy` only restricts `script-src` and `object-src`, leaving stylesheet sources unrestricted โ€” meaning these external style loads bypass CSP scrutiny. Loading remote stylesheets also opens a risk of supply-chain style injection if any CDN is compromised.

reader/index.html (Line 1)
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/4.7.0/css/font-awesome.min.css"><link rel="stylesheet" href="https://stackpath.bootstrapcdn.com/bootstrap/4.4.1/css/bootstrap.min.css"  integrity="sha384-Vkoo8x4CGsO3+Hhxv8T/Q5PaXtkKtu6ug5TOeNV6gBiFeWPGFN9MuhOf23Q9Ifjh" crossorigin="anonymous"><link href="https://fonts.googleapis.com/css2?family=IBM+Plex+Sans&display=swap" rel="stylesheet">

By severity

Critical0
High2
Medium4
Low1

Versions scanned

Showing 2 of 3 scanned versions with more than one unique finding. Counts are unique findings that include each version.

Extension VersionCode Review Findings
1.1.93
1.1.84

Files with findings

4 distinct paths โ€” top paths by unique finding count:

  • background.js3
  • reader/index.html2
  • content.js1
  • reader/reader.js1
S.No.
Category
Severity
File
Summary
Found in Version
1Remote Code Loading
high
background.js (line 164)The background page pulls and executes JavaScript directly from `https://www.google-analytics.com/analytics.js`. Remote script execution inside a privileged extension context is a serious supply-chain risk because theโ€ฆ
2Tracking
high
background.js (line 3)The background page implements Google Analytics tracking (UA-211039558-1) with `ga('set','checkProtocolTask',null)` โ€” a well-known technique to disable GA's built-in protocol validation check, which normally prevents โ€ฆ
3Tracking
medium
reader/index.html (line 1)The extension UI imports third-party stylesheets and fonts from public CDNs and Google Fonts every time the reader page is opened. These requests expose extension usage metadata to external parties and let remote servโ€ฆ
4Tracking
medium
reader/reader.js (line 3924)This code dynamically injects a CSS `@import` from Google Fonts into the reader iframe. It causes outbound requests tied to reading activity and hands a remote service partial control over extension-rendered styling, โ€ฆ
5Tracking
medium
content.js (line 1)This content script runs on every page the user visits (matches `<all_urls>`, all frames) and calls `chrome.storage.sync.get` with the current page's full URL as the lookup key on every single page load. While the staโ€ฆ
6Unauthorized Data Collection
medium
background.js (line 2)Full page URLs are stored as keys in `chrome.storage.sync` (values 0/1 to toggle reader mode). Because `chrome.storage.sync` is backed by Google Sync servers, every URL the user opens in reader mode is transmitted to โ€ฆ
7Tracking
low
reader/index.html (line 1)The reader view page loads CSS and font resources directly from three external CDN domains (cdnjs.cloudflare.com, stackpath.bootstrapcdn.com, fonts.googleapis.com). Each of these requests reveals the user's IP addressโ€ฆ
URLs
21
IPv4
0
IPv6
0

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

Gain full insight into all external connections.

Upgrade for full visibility.

www.google-analytics.com/analytics.jshttps://www.google-analytics.com/analytics.js
www.apache.org/licenses/LICENSE-2.0http://www.apache.org/licenses/LICENSE-2.0
code.google.com/p/arc90labs-readabilityhttp://code.google.com/p/arc90labs-readability
developer.mozilla.org/en-US/docs/Web/API/Node/nodeTypehttps://developer.mozilla.org/en-US/docs/Web/API/Node/nodeType
github.com/whatwg/html/issues/4275,https://github.com/whatwg/html/issues/4275,
mobile.slate.com-http://mobile.slate.com
developer.mozilla.org/en-US/docs/Web/Guide/HTML/Content_categorieshttps://developer.mozilla.org/en-US/docs/Web/Guide/HTML/Content_categories#Phrasing_content
dxr.mozilla.org/mozilla-central/rev/71224049c0b52ab190564d3ea0eab089a159a4cf/accessible/html/HTMLTableAccessible.cpphttps://dxr.mozilla.org/mozilla-central/rev/71224049c0b52ab190564d3ea0eab089a159a4cf/accessible/html/HTMLTableAccessible.cpp#920
github.com/jsdom/jsdom/issues/2580https://github.com/jsdom/jsdom/issues/2580
clients2.google.com/service/update2/crxhttps://clients2.google.com/service/update2/crx
Showing 1 to 10 of 30 rows
Rows per page:

Gain full insight into all external connections.

Upgrade for full visibility.

No IP addresses found
Showing 1 to 3 of 10 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files (scanned top 25 shared text files)

No comparable text files found between these versions.

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.