Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Saved Posts Downloader

alkgglonfjgmdolnjafmbmldmmalhdoi
Risk Score
4.79
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category MediaDownloader
Installs 303
Rating 4.0
Last updated 2026-07-15 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer superwebscraper.com@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • webRequest + cookies + *://*.instagram.com/* enables full session and credential interception on Instagram.
  • Uninstall and install URL hijacks flagged — redirect behaviour on install/uninstall is a monetization/tracking signal.
  • Free-webmail developer email (gmail) with no developer name reduces accountability.
  • No CSP on MV3 extension with DOM-XSS innerHTML sink in content script.
  • Small install base (303) with HIGH-tier permissions is a tail-attack-surface anomaly.

Evidence

  • uninstall_url_hijack + install_url_hijack crx Both install and uninstall URL hooks set; classic monetization/tracking redirect pattern.
  • cookies + webRequest + instagram host manifest cookies & webRequest scoped to instagram.com — capable of full session token exfiltration.
  • no CSP + innerHTML sink crx csp_present==false and dom_sink_innerhtml_userctrl found in content-script; DOM-XSS risk elevated.
  • free-webmail dev email, no developer name store superwebscraper.com@gmail.com with empty developer_name; low accountability.
  • install_perm_anomaly api 303 installs with HIGH-tier permissions (webRequest, cookies, host access) flagged as tail-attack-surface.
  • verified_publisher + featured store Both badges present; provides partial reputation discount but does not negate URL-hijack or session-access risk.
  • js_external_hosts crx References reactjs.org, superwebscraper.com, www.instagram.com — 3 distinct registrable domains.
  • privacy_policy_classification api Policy fetched, scoped, documents data collection, retention and third-party sharing — adequate.

Permissions Breakdown

  • storage low Local state persistence; minimal risk.
  • webRequest high Intercepts network requests; can observe Instagram auth/session traffic.
  • cookies high Access to cookies on instagram.com; session hijack risk.
  • downloads medium Can trigger file downloads; paired with content access raises risk.
  • *://*.superwebscraper.com/* low Dev-controlled domain; limited reach.
  • *://*.instagram.com/* high Full host access to Instagram; combined with cookies+webRequest = high exfil surface.

Pillar Scores

Permissions7.50
Reputation4.50
Network4.00
Webstore7.50
Maintenance0.00
Privacy0.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 09:21
Listing SHA 66c1c785dc90…
Force block — not fired
Score recovered no
Elapsed