πŸ“¦

Rss Subscription Extensio

πŸ” Security Report Available
πŸ‘₯ 400K+ users
πŸ“¦ v2.2.9
πŸ’Ύ 153KiB
πŸ“… 2024-07-04
View on Chrome Web Store

Chrome will indicate if you already have this installed.

Overview

Adds one-click subscription to your toolbar.

Tags

Lifestyle/news lifestyle/news

Privacy Practices

βœ“ Does not collect your data
βœ“ Does not sell your data to third parties
βœ“ Does not use data for unrelated purposes

Security Analysis

Analyzed v2.2.9 Β· Feb 22, 2026 Β· 9 JS files Β· 274 KB scanned

Permissions

tabs storage scripting http://*/* https://*/*

Code Patterns Detected

eval() used β€” can execute arbitrary code Makes HTTP requests

External Connections

github.com www.ecma-international.org www.newsblur.com add.my.yahoo.com feedly.com www.inoreader.com theoldreader.com

Package Contents 61 files Β· 466KB

β–ΎπŸ“_locales156KB
β–ΎπŸ“ar6KB
{}messages.json6KB
β–ΎπŸ“bg7KB
{}messages.json7KB
β–ΎπŸ“ca3KB
{}messages.json3KB
β–ΎπŸ“cs3KB
{}messages.json3KB
β–ΎπŸ“da3KB
{}messages.json3KB
β–ΎπŸ“de3KB
{}messages.json3KB
β–ΎπŸ“el8KB
{}messages.json8KB
β–ΎπŸ“en3KB
{}messages.json3KB
β–ΎπŸ“en_GB3KB
{}messages.json3KB
β–ΎπŸ“es3KB
{}messages.json3KB
β–ΎπŸ“es_4193KB
{}messages.json3KB
β–ΎπŸ“et3KB
{}messages.json3KB
β–ΎπŸ“fi3KB
{}messages.json3KB
β–ΎπŸ“fr3KB
{}messages.json3KB
β–ΎπŸ“he6KB
{}messages.json6KB
β–ΎπŸ“hi7KB
{}messages.json7KB
β–ΎπŸ“hr3KB
{}messages.json3KB
β–ΎπŸ“hu3KB
{}messages.json3KB
β–ΎπŸ“id3KB
{}messages.json3KB
β–ΎπŸ“it3KB
{}messages.json3KB
β–ΎπŸ“ja4KB
{}messages.json4KB
β–ΎπŸ“ko4KB
{}messages.json4KB
β–ΎπŸ“lt3KB
{}messages.json3KB
β–ΎπŸ“lv3KB
{}messages.json3KB
β–ΎπŸ“nb3KB
{}messages.json3KB
β–ΎπŸ“nl3KB
{}messages.json3KB
β–ΎπŸ“pl3KB
{}messages.json3KB
β–ΎπŸ“pt_BR3KB
{}messages.json3KB
β–ΎπŸ“pt_PT3KB
{}messages.json3KB
β–ΎπŸ“ro3KB
{}messages.json3KB
β–ΎπŸ“ru7KB
{}messages.json7KB
β–ΎπŸ“sk4KB
{}messages.json4KB
β–ΎπŸ“sl3KB
{}messages.json3KB
β–ΎπŸ“sr6KB
{}messages.json6KB
β–ΎπŸ“sv3KB
{}messages.json3KB
β–ΎπŸ“th6KB
{}messages.json6KB
β–ΎπŸ“tr3KB
{}messages.json3KB
β–ΎπŸ“uk7KB
{}messages.json7KB
β–ΎπŸ“vi4KB
{}messages.json4KB
β–ΎπŸ“zh_CN3KB
{}messages.json3KB
β–ΎπŸ“zh_TW3KB
{}messages.json3KB
β–ΎπŸ“_metadata8KB
{}verified_contents.json8KB
πŸ“œbackground.js4KB
πŸ“œcommon.js2KB
πŸ“œdoc_start.js460B
πŸ–Όfeed-icon-128x128.png16KB
πŸ–Όfeed-icon-16x16-disabled.png667B
πŸ–Όfeed-icon-16x16.png745B
πŸ–Όfeed-icon-64x64.png3KB
πŸ“œfeed_finder.js3KB
πŸ“œiframe.js243KBlarge
{}manifest.json943B
🌐options.html4KB
πŸ“œoptions.js9KB
🌐popup.html609B
πŸ“œpopup.js3KB
πŸ“œsniff_common.js2KB
🎨style.css423B
🎨subscribe.css657B
🌐subscribe.html2KB
πŸ“œsubscribe.js9KB

What This Extension Does

This extension adds one-click subscription to your toolbar and allows you to easily subscribe to RSS feeds.

Permissions vs. Purpose

  • tabsexpected: Allows the extension to interact with web pages in your browser, including reading and modifying their content.
  • storageexpected: Enables the extension to store data locally on your device, such as subscription settings or feed information.
  • scriptingexpected: Allows the extension to run JavaScript code in the context of web pages you visit, which can be used for dynamic UI elements and other functionality.
  • http://*/*check this: Gives the extension permission to make HTTP requests to any website, which could potentially allow it to access sensitive information or transmit data without user consent.
  • https://*/*check this: Similar to http://*/*, but for HTTPS websites. This is a broad permission that could be used for legitimate purposes, but also raises concerns about potential misuse.

Data Exposure

This extension can access user data stored in web pages and make requests to any website. It sends data to external domains including github.com, www.ecma-international.org, www.newsblur.com, add.my.yahoo.com, feedly.com, www.inoreader.com, theoldreader.com. Some of these transmissions appear to use insecure channels.

Code Behavior Findings

Eval() used

The extension uses eval(), which can execute arbitrary code and potentially allow malicious scripts to run in the context of web pages you visit.

πŸ’‘ eval() is sometimes used for dynamic UI elements or other functionality, but it's generally considered a security risk due to its potential for abuse.

⚠ This usage could be related to the extension's need to dynamically render RSS feed information in the browser.

Makes HTTP requests

The extension makes HTTP requests to external domains, which can potentially allow it to access sensitive information or transmit data without user consent.

πŸ’‘ Making HTTP requests is a common practice for extensions that need to fetch data from external sources, such as RSS feeds.

Transparency Indicators

The developer is not identified. The code does not appear to be heavily obfuscated beyond normal bundling. There is no content security policy in place. The extension has an install base of 400,000 users and the latest version (2.2.9) was released recently.

Bottom Line

This scan found some concerning behavior, including the use of eval() and broad permissions that could be used for malicious purposes. Users should exercise caution when installing this extension and consider reviewing its permissions and code before granting it access to their browser.

Similar Extensions

More in Lifestyle/news β†’
πŸ“¦

Rss Feed Reader

500K+ users
Get a simple overview of your RSS and Atom feeds in the toolbar
Lifestyle/news
πŸ“¦
The most advanced crypto-currency price tracker browser extension. Support major coins such as Bitcoin, Etherium, Solana…
Lifestyle/news
πŸ“¦

Karma Nature

200K+ users
Karma Nature brings you a NewTab with beautiful backgrounds, Time, Date, Weather and Search
Lifestyle/news
πŸ“¦

Gismeteo

200K+ users
Gismeteo Weather Forecast. Real time weather and detailed forecast all round the world
Lifestyle/news