Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Instagram Downloader Pro - Download Video, Story, Reels & Photo

cbnmngfnpibbjobleaghjkdlibjhphlf
Risk Score
2.70
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category MediaDownloader
Installs 4,000
Rating 3.0
Last updated 2026-06-14
Manifest version MV3
CSP present ❌ no
Developer extmax70@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: extension names Instagram (Meta trademark) without confirmed ownership, via free-webmail dev.
  • Developer is unverified free-webmail (gmail) with no business identity; high abandonment/transfer risk.
  • Privacy policy admits data collection AND third-party sharing without scoping retention; inadequate.
  • ToS-violation risk: MediaDownloader scraping Instagram violates Instagram/Meta platform terms of service.
  • No CSP present (MV3 mitigates partially) and policy on GitHub repo, not dev-controlled domain.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; brands_mentioned=['instagram']; confirmed_owner=false; dev domain is gmail.com.
  • free_webmail_developer store developer_email=extmax70@gmail.com; no verified business identity or domain.
  • privacy_policy_data_collection_third_party api Classification: scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
  • tos_violation_media_downloader store Extension scrapes Instagram media; violates Meta/Instagram terms of service (v3.1 rule 7).
  • no_csp manifest content_security_policy=null; MV3 enforces strict default but no explicit CSP declared.
  • host_permissions_instagram manifest host_permissions: *://*.instagram.com/*, *://*.cdninstagram.com/*; content_scripts on instagram.com.
  • low_rating store Rating=3.0; insufficient rating_count data to apply >=50-rating penalty threshold.
  • privacy_policy_on_github api Policy hosted on github.com/seven-element repo, not dev-controlled domain; retention not disclosed.

Permissions Breakdown

  • activeTab low Scoped to user-initiated tab interaction only.
  • storage low Local data persistence; low standalone risk.
  • downloads medium Can write files to user disk; core to stated function.
  • sidePanel low UI surface only; low risk.
  • *://*.instagram.com/* medium Broad host access on Instagram; matches stated download function.
  • *://*.cdninstagram.com/* medium CDN host for Instagram media; justified for download use case.

Pillar Scores

Permissions2.80
Reputation7.50
Network0.00
Webstore7.00
Maintenance0.00
Privacy2.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-15 14:04
Listing SHA f9f865955fea…
Force block — not fired
Score recovered no
Elapsed 21.8s