Is RSSHub Radar safe?

Clean risk

RSSHub Radar reads each visited page's HTML to find RSS and RSSHub feed candidates.

When you open or switch tabs, the background worker asks the content script for the page's full HTML and URL, then uses stored RSSHub rules and an offscreen page to compute feed suggestions. The content script also checks feed links found on the page so the extension can show a badge, with no confirmed recipient endpoint for the page HTML.

DIYgodv2.2.0Chrome Web Store
0Risk
Who publishes it

DIYgod - no other listings under this identity, 2 shared hostnames

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
DIYgod

Shared hosts - 2 hostnames

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

ckc.ftqq.com
Also called by 3 other listings, including Check酱
commafeed.com
Also called by 3 other listings, including CommaFeed

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 2.2.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every secure site you visit

    https://*/*

  • See the address and title of every tab you have open

    tabs

  • Run hidden pages in the background

    offscreen

  • Store data in your browser

    storage

  • Schedule its own background tasks

    alarms

Updated 30 September 2026kefjpfngnndepjbopdmoebkipbgkggaa