Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Video Downloader for U

dkbccihpiccbcheieabdbjikohfdfaje
Risk Score
4.68
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VideoDownloader
Installs 90,000
Rating 3.9
Last updated 2025-11-27 (7 months ago)
Manifest version MV3
CSP present ❌ no
Developer petersunben@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection and third-party sharing without scoping to this extension (generic policy, score=10.0).
  • Three medium-severity jQuery CVEs (3.2.1 < 3.5.0) bundled without update; XSS risk in DOM-manipulation lib.
  • webRequest + <all_urls> + content_scripts on all URLs: full network interception on every site.
  • Developer identified only by free Gmail with no name; verified_publisher badge does not override identity gaps.
  • new Function() constructor present in background, content, and popup scripts; dynamic code execution surface.

Evidence

  • privacy_policy_generic_with_3p_sharing api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (D rule).
  • cve_jquery_3_medium crx jquery@3.2.1 has 3 medium CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); fixed_in 3.5.0.
  • csp_absent_mv3 manifest No content_security_policy declared; MV3 default applies but jquery+no CSP triggers v2e +2.0 code quality.
  • webrequest_all_urls manifest webRequest HIGH perm paired with <all_urls> host_permissions; ×1.2 amplifier applied.
  • free_webmail_dev_no_name store developer_email=petersunben@gmail.com; developer_name empty; +1.5 free-webmail dev.
  • verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; discounts applied but capped by gmail identity.
  • function_constructor_3_files crx new Function() in background.js, content.js, popup.js — dynamic code execution in all major contexts.
  • installs_90k store 90,000 installs; +1.0 webstore reach signal (>10K tier).

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@3.2.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.2.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.2.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • storage low Stores extension state locally; minimal risk.
  • tabs medium Can read tab URLs and metadata; useful for video detection.
  • downloads medium Triggers file downloads; core to stated function.
  • webRequest high Intercepts all network requests across all URLs; broad surveillance capability.
  • <all_urls> (host_permissions) high Content scripts and webRequest operate on every site the user visits.

Pillar Scores

Permissions5.50
Reputation5.50
Network2.00
Webstore2.50
Maintenance1.50
Privacy10.00
Code Quality2.50
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:27
Listing SHA eee5807de28d…
Force block — not fired
Score recovered no
Elapsed 29.1s