X Media Downloader - Twitter Media Downloader
akhckkpbjonlaacapohphmdfoikibkbg
Risk Score
5.55
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy admits data collection + third-party sharing but is NOT scoped to this extension — D rule fires +10.0.
- Brand impersonation: 'Twitter' brand mentioned, not a confirmed owner, not verified publisher — +2.0 Reputation.
- webRequest on *.x.com / *.twitter.com enables interception of authenticated social-media sessions.
- jquery@3.2.1 carries 3 medium XSS CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023), not yet patched.
- new Function() constructor pattern found in 4 JS files raises dynamic code execution risk.
Evidence
- privacy_policy_generic_admits_sharing api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → D rule +10.0 privacy.
- brand_impersonation store brand_mention.is_impersonation=true for 'twitter'; not verified_publisher, not featured → +2.0 Reputation.
- jquery_cve_moderate_x3 crx jquery@3.2.1 has CVE-2019-11358, CVE-2020-11022, CVE-2020-11023 (all moderate); fixed_in 3.4/3.5.
- function_constructor_multi_file crx new Function() constructor found in background.js, contentScript.js, injected.js, popup.js.
- webrequest_social_media_host manifest webRequest + host_permissions on *.x.com and *.twitter.com allows full request inspection on social platform.
- js_external_hosts_diverse crx 9 external JS hosts including api.parse.com, buy.extensionsbox.com, www.youtube.com — >3 distinct domains.
- no_developer_name store developer_name is empty string; only email support@extensionsbox.com available.
- csp_present_mv3 manifest CSP: script-src 'self'; object-src 'self' — no unsafe-eval/inline; MV3 so no +2.0 MV2 penalty.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@3.2.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.2.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.2.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- storage low Local key-value storage; low direct harm.
- identity low OAuth token access; limited scope without broad host.
- downloads medium Can initiate downloads to user filesystem; expected for media downloader.
- webRequest high Can observe all network requests on host_permissions scope; paired with twitter/x host access.
- *://xmediadownloader.com/* medium Permits content injection and request interception on dev's own backend domain.
- *://*.x.com/* high Full content script + webRequest access on X/Twitter — can read tweets, DMs, credentials.
- *://*.twitter.com/* high Full content script + webRequest access on Twitter — same high-sensitivity surface as x.com.
Pillar Scores
Permissions5.50
Reputation6.50
Network3.50
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality2.50
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:17
Listing SHA
60e45bfb6b04…
Force block
— not fired
Score recovered
no
Elapsed
32.1s