Automatic 4K/HD for Youtube
dclmmkinjdaochjinbhanlipdpmkdhfb
Risk Score
8.14
Risk Level:
Critical
Recommendation:
🚫 BLOCK
Top Risks
- Broad <all_urls> + http/https/* host access far exceeds YouTube-only stated function; scope mismatch is critical.
- MV2 extension abandoned 39 months ago with no CSP on script-src eval; jquery@3.2.1 has 3 medium XSS CVEs unfixed.
- YouTube brand impersonation by unverified Gmail developer with no business identity.
- Privacy policy on Google Sites admits data collection and third-party sharing without extension-specific scope.
- Uninstall and install URL hijack flags set; external JS host cdn.automatic-hd.info is non-Google third party.
Evidence
- broad_host_permissions manifest <all_urls>, http://*/*, https://*/* far exceed youtube.com content_scripts scope.
- mv2_no_csp_eval manifest MV2 + CSP allows unsafe-eval on style-src and connect-src:* with remote GA host.
- cve_jquery_3_2_1 crx jquery@3.2.1 has 3 moderate XSS CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); fixed_in 3.5.0.
- abandoned_extension store Last updated May 2023; 39 months stale. MV2 with unpatched CVEs.
- brand_impersonation store Developer 'Youtube Auto HD' on gmail.com impersonates YouTube brand; confirmed_owner=false.
- generic_privacy_policy api Policy on sites.google.com: scope_extension=false, data_collection=true, third_party_sharing=true.
- install_uninstall_hijack crx uninstall_url_hijack=true and install_url_hijack=true flagged in manifest scan.
- external_cdn crx cdn.automatic-hd.info is an unverified third-party JS host loaded by extension.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@3.2.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.2.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.2.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- alarms low Scheduling only; minimal risk.
- storage low Local data persistence; low risk.
- tabs medium Can enumerate open tabs and URLs.
- unlimitedStorage low Storage quota extension; low standalone risk.
- http://*/* high Broad host access across all HTTP sites.
- https://*/* high Broad host access across all HTTPS sites.
- notifications low Display notifications; low risk.
- <all_urls> high Unrestricted access to all URLs; highest host permission risk.
Pillar Scores
Permissions8.00
Reputation8.50
Network8.00
Webstore8.50
Maintenance10.00
Privacy10.00
Code Quality2.00
CVE Exposure4.50
Scoring History
| sssiednfaeab911dp727562726963xsx | 8.08 | Critical | block | 2026-08-30 |
| v3.6 | 8.14 | Critical | block | 2026-08-28 |
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 07:59
Listing SHA
3a9cd096eae5…
Force block
— not fired
Score recovered
no
Elapsed
—