Image downloader - Imageye
agionbommeaifngbhincahgmoflcikhm
Risk Score
4.67
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Broad host access (<all_urls> + scripting + webRequest) enables full page reading and request interception on every site visited.
- No CSP + dynamic script creation and new Function() constructors increase code-injection attack surface if extension is compromised.
- Gmail developer identity with no business name; verified publisher badge present but identity transparency is limited.
- Privacy policy fetched but does not scope to this extension nor disclose data collection — third-party silence flag raised.
- Install/uninstall URL hijack redirects to imageye.net; 8 external JS hosts including www.gogather.mobi (unverified domain).
Evidence
- broad_host_permissions manifest http://*/*, https://*/*, <all_urls> all declared; content_scripts also match all URLs.
- webRequest_high_perm manifest webRequest paired with <all_urls> allows passive interception of all HTTP traffic.
- no_csp crx content_security_policy is null; no CSP hardening on MV3 extension.
- dynamic_script_and_new_function crx popup.js and 733.js use new Function() constructor and dynamic <script> creation.
- gmail_dev_no_name store developer_email=meaganamrach@gmail.com; developer_name is empty string.
- privacy_policy_not_extension_scoped api Policy fetched (45 KB) but scope_extension=false, data_collection=false; third_party_silence=true.
- install_uninstall_url_hijack crx onInstalled → imageye.net/extension/installed/; onUninstalled → imageye.net/extension/uninstalled/.
- verified_publisher_featured store verified_publisher=true, is_featured_by_google=true; partially mitigates reputation risk.
Permissions Breakdown
- activeTab low Scoped to user-invoked tab; limited blast radius.
- downloads medium Can write files to disk; core to stated function.
- storage low Local preference storage; low standalone risk.
- webRequest high Can observe all HTTP requests across all URLs; significant surveillance capability.
- scripting high Arbitrary script injection into any page via broad host perms.
- declarativeNetRequest medium Can block/redirect network requests; lower risk than webRequestBlocking.
- sidePanel low UI surface only; no additional data access.
- http://*/* high Broad host access covering all HTTP sites; amplifies scripting/webRequest risk.
- https://*/* high Broad host access covering all HTTPS sites; amplifies scripting/webRequest risk.
- <all_urls> high Redundant broad host grant; ensures no URL is excluded.
Pillar Scores
Permissions5.50
Reputation5.50
Network4.00
Webstore4.50
Maintenance0.00
Privacy9.00
Code Quality5.50
CVE Exposure0.00
Scoring History
| fsssiedxnc28256feza'nc28256fezsssiedx | 5.45 | Medium | review | 2026-09-02 |
| sssiedn5cc1c921dp727562726963xsx | 5.54 | Medium | review | 2026-09-02 |
| sssiedn3c751cd8dp727562726963xsx | 5.13 | Medium | review | 2026-08-30 |
| <fsssiedxi | 4.97 | Medium | review | 2026-08-22 |
| fsssiedx<sssiedx | 5.01 | Medium | review | 2026-08-22 |
| fsssiedxa'sssiedx | 5.06 | Medium | review | 2026-08-05 |
| sssieddrubricxsx | 5.21 | Medium | review | 2026-08-05 |
| v3.6 | 4.67 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:16
Listing SHA
7178e87636af…
Force block
— not fired
Score recovered
no
Elapsed
28.5s