Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

X Media Downloader - Twitter Media Downloader

akhckkpbjonlaacapohphmdfoikibkbg
Risk Score
5.55
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category MediaDownloader
Installs 10,000
Rating 3.7
Last updated 2026-06-13
Manifest version MV3
CSP present ✅ yes
Developer support@extensionsbox.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection + third-party sharing but is NOT scoped to this extension — D rule fires +10.0.
  • Brand impersonation: 'Twitter' brand mentioned, not a confirmed owner, not verified publisher — +2.0 Reputation.
  • webRequest on *.x.com / *.twitter.com enables interception of authenticated social-media sessions.
  • jquery@3.2.1 carries 3 medium XSS CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023), not yet patched.
  • new Function() constructor pattern found in 4 JS files raises dynamic code execution risk.

Evidence

  • privacy_policy_generic_admits_sharing api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → D rule +10.0 privacy.
  • brand_impersonation store brand_mention.is_impersonation=true for 'twitter'; not verified_publisher, not featured → +2.0 Reputation.
  • jquery_cve_moderate_x3 crx jquery@3.2.1 has CVE-2019-11358, CVE-2020-11022, CVE-2020-11023 (all moderate); fixed_in 3.4/3.5.
  • function_constructor_multi_file crx new Function() constructor found in background.js, contentScript.js, injected.js, popup.js.
  • webrequest_social_media_host manifest webRequest + host_permissions on *.x.com and *.twitter.com allows full request inspection on social platform.
  • js_external_hosts_diverse crx 9 external JS hosts including api.parse.com, buy.extensionsbox.com, www.youtube.com — >3 distinct domains.
  • no_developer_name store developer_name is empty string; only email support@extensionsbox.com available.
  • csp_present_mv3 manifest CSP: script-src 'self'; object-src 'self' — no unsafe-eval/inline; MV3 so no +2.0 MV2 penalty.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@3.2.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.2.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.2.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • storage low Local key-value storage; low direct harm.
  • identity low OAuth token access; limited scope without broad host.
  • downloads medium Can initiate downloads to user filesystem; expected for media downloader.
  • webRequest high Can observe all network requests on host_permissions scope; paired with twitter/x host access.
  • *://xmediadownloader.com/* medium Permits content injection and request interception on dev's own backend domain.
  • *://*.x.com/* high Full content script + webRequest access on X/Twitter — can read tweets, DMs, credentials.
  • *://*.twitter.com/* high Full content script + webRequest access on Twitter — same high-sensitivity surface as x.com.

Pillar Scores

Permissions5.50
Reputation6.50
Network3.50
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality2.50
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:17
Listing SHA 60e45bfb6b04…
Force block — not fired
Score recovered no
Elapsed 32.1s