Is EPUBReader safe?

Low risk

EPUBReader exposes a reader page that any website can load to send HTTP requests to arbitrary URLs, including internal network addresses.

The extension's reader.html page is declared as a web-accessible resource available to all origins. Any web page can embed it with a crafted filename= URL parameter, causing the extension to make an XMLHttpRequest to an attacker-specified URL — including local network addresses such as 192.168.x.x or 127.0.0.1 — using the extension's broad host permissions. The response body is not readable cross-origin, but the request itself is sent, enabling blind server-side request forgery.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

epubreaderv2.1.1Chrome Web Store
20Risk
Who publishes it

epubreader - no other listings under this identity, 1 shared hostname

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
epubreader

Shared hosts - 1 hostname

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

epubread.com
Also called by 1 other listing: EPUBReader

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 2.1.1. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    <all_urls>

  • Block and redirect the requests your browser makes

    declarativeNetRequest

  • Start, monitor and manage your downloads

    downloads

  • Store data in your browser

    storage

Updated 30 September 2026jhhclmfgfllimlhabjkgkeebkbiadflb