Media Downloader
aklijicmhlmfioogfbemefilfdffijcl
Risk Score
2.68
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and third-party sharing.
- Free webmail developer (gmail.com) with no verified business identity or privacy domain.
- scripting + <all_urls> enables script injection on every site the user visits.
- Rating 3.3 with no verified publisher badge; identity accountability low.
- MediaDownloader category may implicate ToS violations on YouTube/major platforms.
Evidence
- privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true — scores max Privacy pillar.
- free_webmail_developer store Developer email rtc0d3r@gmail.com; no verified publisher badge; no business domain.
- broad_host_access manifest <all_urls> host permission paired with scripting permission allows page script injection on all sites.
- is_featured_by_google store Extension carries Google Featured badge, partially mitigating reputation risk.
- code_clean crx code_findings_raw empty, obfuscation_score=0.0, no external JS hosts beyond YouTube/Chrome docs.
- cve_clean crx cve_findings_raw empty; no bundled vulnerable libraries detected.
- threat_intel_clean api No bad_host_hits, affiliate_hits, or monetization_hits; js_external_hosts limited to YouTube and developer.chrome.com.
- rating_below_threshold store Rating 3.3; no confirmed review red-flag matches but below acceptable threshold with unverified dev identity.
Permissions Breakdown
- activeTab low Access to current tab only on user gesture; limited scope.
- sidePanel low UI panel display only; no data access.
- downloads medium Can initiate file downloads to user's disk; expected for MediaDownloader.
- scripting medium Can inject scripts into pages; paired with <all_urls> increases reach.
- storage low Local extension storage only; no exfil on its own.
- contextMenus low Adds right-click menu items; minimal risk.
- <all_urls> (host_permission) high Broad host access across all sites; enables scripting injection everywhere.
- https://www.gstatic.com/ (host_permission) low Scoped to Google static CDN; narrow and expected.
Pillar Scores
Permissions4.30
Reputation6.50
Network0.00
Webstore1.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Scoring History
| v3.6 | 2.68 | Low | review | 2026-06-16 |
| v3.4-rev | 4.26 | Medium | review | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:17
Listing SHA
f2ecb932a5f8…
Force block
— not fired
Score recovered
no
Elapsed
22.9s