"This add-on is not actively monitored for security by Mozilla. Make sure you trust it before installing."
https://addons.mozilla.org/en-US/firefox/addon/fakespot-fake...
"This add-on is not actively monitored for security by Mozilla. Make sure you trust it before installing."
https://addons.mozilla.org/en-US/firefox/addon/fakespot-fake...
None of the ones I reported have had their recommended status revoked, several ones have since even been allowed to publish new versions where the same violations are still present and even a few published updates that introduced additional violations.
To Mozilla: If you want to change the world, start with yourself.
To the rest: Whenever you install or update an extension, always go through its published source first. You can get to it by right-clicking the install/download button to "save as" and then simply unpacking the xpi file.
Could you publish these publicly anywhere, so that we can do for ourselves the job that Mozilla apparently is failing to do (while claiming to)?
https://addons.mozilla.org/en-US/firefox/addon/giphy-for-fir...
https://addons.mozilla.org/en-US/firefox/addon/tabliss/
https://addons.mozilla.org/en-US/firefox/addon/youtube-subsc...
The official policies can be found here:
https://extensionworkshop.com/documentation/publish/add-on-p...
Some highlights of commonly "forgotten" rules:
> No Surprises
> Add-ons must be self-contained and not load remote code for execution.
> Add-ons must limit data collection to what is necessary for functionality [...] Data includes all information the add-on collects, regardless of the manner.
> Collecting, or facilitating the collection of ancillary information (e.g. any data not required for the add-on’s functionality as stated in the description) is prohibited.
> Modifying web content or facilitating redirects to include affiliate promotion tags is not permitted