Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Discord Media Downloader – Discord Video & Image Download Tool

bgjnhncmompmadaalhdflfmdhfamkgaf
Risk Score
4.32
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category MediaDownloader
Installs 1,000
Rating 4.6
Last updated 2026-05-27 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer jinchaoh@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: extension uses 'Discord' brand in name/domain with no verified ownership.
  • Privacy policy hosted on discordkit.com is only 179 chars, not scoped to this extension, no retention info.
  • Free-webmail dev (gmail) with no developer name — accountability gap.
  • Content script injected into extensionpay.com (payment processor) via third-party host.
  • Uninstall URL hijack detected — redirect target unverified.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true, confirmed_owner=false; developer domain is gmail.com not discord.com.
  • free_webmail_dev_no_name manifest developer_email=jinchaoh@gmail.com, developer_name empty; no verifiable business identity.
  • privacy_policy_inadequate store Policy 179 chars, scope_extension=false, data_collection=false, retention=false; effectively non-scoped.
  • uninstall_url_hijack crx uninstall_url_hijack=true; redirects to unverified third-party URL on uninstall.
  • extensionpay_content_script manifest content_scripts_matches includes https://extensionpay.com/* — third-party payment page injection.
  • function_constructor_in_jszip crx new Function() in lib/jszip.min.js; low-risk in archive lib context but dynamic code execution present.
  • verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; partially offsets reputation concerns.
  • no_csp manifest csp_present=false on MV3; strict default applies but no explicit policy declared.

Permissions Breakdown

  • storage low Local key-value storage; low direct harm.
  • downloads medium Can trigger file downloads to user disk; fits stated downloader function.
  • sidePanel low Adds side-panel UI; no data-access capability.
  • alarms low Schedules background tasks; low standalone risk.
  • *://*.discord.com/* high Full read/write access to Discord web app including messages and auth tokens.
  • *://*.discord.gg/* medium Invite-link pages; limited sensitive content but still Discord origin.
  • *://cdn.discordapp.com/* medium CDN for media; needed for downloads but grants request interception.
  • *://media.discordapp.net/* medium Media CDN; similar to above, scoped to stated function.
  • https://extensionpay.com/* medium Third-party payment processor injected via content script; payment-data exposure risk.

Pillar Scores

Permissions3.50
Reputation6.50
Network3.50
Webstore5.50
Maintenance0.00
Privacy9.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:19
Listing SHA 36f5bdbc012a…
Force block — not fired
Score recovered no
Elapsed 26.2s