Image Downloader - Save pictures
daeljdgmllhgmbdkpgnaojldjkdgkbjg
Risk Score
3.02
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- webRequest + <all_urls>: extension can observe all HTTP/S requests across every site visited.
- jquery@3.1.1 bundles 3 medium-severity XSS CVEs; no CSP to mitigate exploitation surface.
- Free-webmail developer (Gmail) with no verified business identity raises accountability gap.
- Privacy policy discloses third-party data sharing without scoping retention, reducing trust.
- External JS host (jqueryui.com) loaded at runtime; no CSP to restrict script sources.
Evidence
- broad_host_permissions manifest host_permissions includes http://*/*, https://*/*, <all_urls> — full cross-site reach for webRequest and scripting.
- jquery_cve_bundle crx jquery@3.1.1 bundled (js/libs/jquery-3.1.1.min.js); 3 medium CVEs unfixed below 3.5.0.
- no_csp manifest content_security_policy is null on MV3; no script-src restriction mitigating CVE-exposed jQuery.
- external_js_host crx js_external_hosts contains jqueryui.com; remote script dependency with no CSP pin.
- free_webmail_dev store developer_email is porterlarsgren@gmail.com; no business domain verified.
- privacy_policy_gaps api Policy fetched; scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
- verified_publisher_featured store verified_publisher=true and is_featured_by_google=true; partially offsets reputation risk.
- webRequest_permission manifest webRequest declared alongside <all_urls>; can inspect all network traffic passively.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@3.1.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.1.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.1.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- storage low Saves user preferences; minimal risk.
- activeTab medium Accesses current tab on user action; scoped but enables page reading.
- scripting medium Can inject scripts into pages; required for image detection but capable of abuse.
- downloads medium Core function for image saving; can write to user filesystem.
- webRequest high Observes all HTTP requests across all URLs; high surveillance capability.
- declarativeNetRequest medium Can block/redirect network requests declaratively; lower risk than webRequestBlocking.
- http://*/* high Broad host access across all HTTP sites amplifies webRequest and scripting risk.
- https://*/* high Broad host access across all HTTPS sites; paired with webRequest raises risk.
- <all_urls> high Explicit all-URLs host permission; maximizes reach of every capability.
Pillar Scores
Permissions4.50
Reputation3.50
Network2.00
Webstore2.50
Maintenance0.00
Privacy2.00
Code Quality2.00
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:25
Listing SHA
20d5af8cbb73…
Force block
— not fired
Score recovered
no
Elapsed
26.8s