Video Scrubber for Instagram
apondjajmejlodhkaenofcicoiiekghf
Risk Score
6.19
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- No update date available — extension may be abandoned; maintenance pillar at maximum.
- jquery@1.12.4 bundles 4 medium XSS CVEs; no CSP amplifies DOM-XSS risk on Instagram pages.
- Privacy policy fetched but does not scope to this extension; admits third-party sharing without disclosure.
- Brand impersonation: 'Instagram' in name, developer not a confirmed owner; verified+featured does not clear this.
- install_url_hijack and uninstall_url_hijack both flagged; onInstalled/onUninstalled open 3rd-party URLs.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true for 'instagram'; developer not confirmed owner.
- cve_jquery_medium_x4 crx jquery@1.12.4 carries CVE-2019-11358, CVE-2020-11022, CVE-2020-11023, CVE-2015-9251 (all medium).
- no_csp_plus_cve_dom_sink crx csp_present=false; dom_sink_innerhtml_userctrl in InstaUtils.js with CVE-laden jQuery = elevated XSS risk.
- install_uninstall_hijack crx install_url_hijack=true and uninstall_url_hijack=true; targets not disclosed.
- privacy_policy_inadequate store Policy fetched; scope_extension=false, data_collection=false, third_party_sharing=true → +9.0 privacy.
- no_last_updated store months_since_update=null; last_updated empty; maintenance scored at maximum (10.0).
- external_js_hosts crx js_external_hosts: chrome.google.com, docs.google.com, getbootstrap.com, www.georgemike.com (4 domains).
- verified_publisher_featured store verified_publisher=true, is_featured_by_google=true; caps applied but impersonation+CVEs limit discount.
CVE Exposures (4)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@1.12.4 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@1.12.4 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@1.12.4 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@1.12.4 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- storage low Stores local extension state; no cross-site data risk.
- host:https://instagram.com/* medium Content script runs on Instagram pages; scoped to single domain.
- host:https://*.instagram.com/* medium Covers all Instagram subdomains; required for stated function.
Pillar Scores
Permissions2.30
Reputation5.50
Network3.50
Webstore4.50
Maintenance10.00
Privacy9.00
Code Quality6.50
CVE Exposure6.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:18
Listing SHA
006ec76a3532…
Force block
— not fired
Score recovered
no
Elapsed
29.6s