Video Downloader for U
dkbccihpiccbcheieabdbjikohfdfaje
Risk Score
4.68
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy admits data collection and third-party sharing without scoping to this extension (generic policy, score=10.0).
- Three medium-severity jQuery CVEs (3.2.1 < 3.5.0) bundled without update; XSS risk in DOM-manipulation lib.
- webRequest + <all_urls> + content_scripts on all URLs: full network interception on every site.
- Developer identified only by free Gmail with no name; verified_publisher badge does not override identity gaps.
- new Function() constructor present in background, content, and popup scripts; dynamic code execution surface.
Evidence
- privacy_policy_generic_with_3p_sharing api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (D rule).
- cve_jquery_3_medium crx jquery@3.2.1 has 3 medium CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); fixed_in 3.5.0.
- csp_absent_mv3 manifest No content_security_policy declared; MV3 default applies but jquery+no CSP triggers v2e +2.0 code quality.
- webrequest_all_urls manifest webRequest HIGH perm paired with <all_urls> host_permissions; ×1.2 amplifier applied.
- free_webmail_dev_no_name store developer_email=petersunben@gmail.com; developer_name empty; +1.5 free-webmail dev.
- verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; discounts applied but capped by gmail identity.
- function_constructor_3_files crx new Function() in background.js, content.js, popup.js — dynamic code execution in all major contexts.
- installs_90k store 90,000 installs; +1.0 webstore reach signal (>10K tier).
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@3.2.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.2.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.2.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- storage low Stores extension state locally; minimal risk.
- tabs medium Can read tab URLs and metadata; useful for video detection.
- downloads medium Triggers file downloads; core to stated function.
- webRequest high Intercepts all network requests across all URLs; broad surveillance capability.
- <all_urls> (host_permissions) high Content scripts and webRequest operate on every site the user visits.
Pillar Scores
Permissions5.50
Reputation5.50
Network2.00
Webstore2.50
Maintenance1.50
Privacy10.00
Code Quality2.50
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:27
Listing SHA
eee5807de28d…
Force block
— not fired
Score recovered
no
Elapsed
29.1s