Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Automatic 4K/HD for Youtube

dclmmkinjdaochjinbhanlipdpmkdhfb
Risk Score
8.14
Risk Level: Critical
Recommendation: 🚫 BLOCK
Category Entertainment
Installs 264
Rating 4.4
Last updated 2023-05-05 (39 months ago)
Manifest version MV2
CSP present ✅ yes
Developer szczege626@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Broad <all_urls> + http/https/* host access far exceeds YouTube-only stated function; scope mismatch is critical.
  • MV2 extension abandoned 39 months ago with no CSP on script-src eval; jquery@3.2.1 has 3 medium XSS CVEs unfixed.
  • YouTube brand impersonation by unverified Gmail developer with no business identity.
  • Privacy policy on Google Sites admits data collection and third-party sharing without extension-specific scope.
  • Uninstall and install URL hijack flags set; external JS host cdn.automatic-hd.info is non-Google third party.

Evidence

  • broad_host_permissions manifest <all_urls>, http://*/*, https://*/* far exceed youtube.com content_scripts scope.
  • mv2_no_csp_eval manifest MV2 + CSP allows unsafe-eval on style-src and connect-src:* with remote GA host.
  • cve_jquery_3_2_1 crx jquery@3.2.1 has 3 moderate XSS CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); fixed_in 3.5.0.
  • abandoned_extension store Last updated May 2023; 39 months stale. MV2 with unpatched CVEs.
  • brand_impersonation store Developer 'Youtube Auto HD' on gmail.com impersonates YouTube brand; confirmed_owner=false.
  • generic_privacy_policy api Policy on sites.google.com: scope_extension=false, data_collection=true, third_party_sharing=true.
  • install_uninstall_hijack crx uninstall_url_hijack=true and install_url_hijack=true flagged in manifest scan.
  • external_cdn crx cdn.automatic-hd.info is an unverified third-party JS host loaded by extension.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@3.2.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.2.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.2.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • alarms low Scheduling only; minimal risk.
  • storage low Local data persistence; low risk.
  • tabs medium Can enumerate open tabs and URLs.
  • unlimitedStorage low Storage quota extension; low standalone risk.
  • http://*/* high Broad host access across all HTTP sites.
  • https://*/* high Broad host access across all HTTPS sites.
  • notifications low Display notifications; low risk.
  • <all_urls> high Unrestricted access to all URLs; highest host permission risk.

Pillar Scores

Permissions8.00
Reputation8.50
Network8.00
Webstore8.50
Maintenance10.00
Privacy10.00
Code Quality2.00
CVE Exposure4.50

Scoring History

sssiednfaeab911dp727562726963xsx 8.08 Critical block 2026-08-30
v3.6 8.14 Critical block 2026-08-28

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 07:59
Listing SHA 3a9cd096eae5…
Force block — not fired
Score recovered no
Elapsed