Image downloader - picture and photos saver
cbnhnlbagkabdnaoedjdfpbfmkcofbcl
Risk Score
4.18
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Broad host permissions (<all_urls>, http://*/* , https://*/*) combined with webRequest on MV3 — can observe all browsing traffic.
- Gmail developer with no verified business identity; free-webmail dev raises accountability concerns.
- No CSP defined; DOM-XSS innerHTML sink in popup JS increases XSS risk if page content is unsanitized.
- Privacy policy hosted on Google Sites free hosting, lacks data retention disclosure.
- 17 months since last update approaches stale threshold; no changelog visible.
Evidence
- broad_host_permissions manifest host_permissions include http://*/*, https://*/*, <all_urls> — full browsing reach.
- webRequest_broad manifest webRequest declared alongside <all_urls>; can observe all network activity.
- free_webmail_dev store Developer email hagelakimosy@gmail.com; no verified business domain.
- no_csp crx content_security_policy is null; MV3 default applies but no hardened policy set.
- dom_xss_sink crx innerHTML assignment in popup/index.js — potential DOM-XSS if input unsanitized.
- privacy_policy_free_hosting store Policy on Google Sites free hosting; no retention clause; third_party_silence=true.
- is_featured_by_google store Extension carries Google Featured badge, partially offsetting reputation concerns.
- stale_17mo store Last updated January 2025; 17 months since update, approaching high-risk staleness band.
Permissions Breakdown
- storage low Stores user preferences; minimal risk.
- activeTab medium Access to current tab on user action; scoped but non-trivial.
- scripting medium Can inject scripts into pages; elevated with broad host access.
- downloads medium Can save files to disk; core to stated function but abusable.
- webRequest high Intercept/observe all network requests across all URLs.
- declarativeNetRequest medium Can block/redirect requests declaratively; lower risk than webRequest.
- http://*/* high Broad host access to all HTTP sites.
- https://*/* high Broad host access to all HTTPS sites.
- <all_urls> high Redundant with above; grants access to every URL including chrome-extension.
Pillar Scores
Permissions5.50
Reputation6.50
Network2.00
Webstore2.50
Maintenance3.50
Privacy2.00
Code Quality2.00
CVE Exposure0.00
Scoring History
| sssieddrubricxsx | 5.17 | Medium | review | 2026-07-31 |
| v3.6 | 4.18 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:22
Listing SHA
7f8c4a5d329d…
Force block
— not fired
Score recovered
no
Elapsed
24.7s