Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Bulk Media Downloader

ehfdcgbfcboceiclmjaofdannmjdeaoi
Risk Score
5.24
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category MediaDownloader
Installs 100,000
Rating 3.8
Last updated 2026-01-05 (7 months ago)
Manifest version MV3
CSP present ❌ no
Developer inb.cor@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — does not scope to this extension, admits data collection and third-party sharing (+10 privacy pillar).
  • webRequest + *://*/*ombination allows interception of all network traffic on every site visited.
  • Install and uninstall URL hijack flags set; developer uses free Gmail address with no verified business domain.
  • No CSP on MV3 extension; 4-country JS host geo-diversity (CA, IN, NL, US) with external hosts including non-obvious domains.
  • Featured by Google partially offsets reputation concerns, but Gmail dev email and no verified publisher leave elevated identity risk.

Evidence

  • privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • webRequest_broad_host manifest webRequest + *://*/* = HIGH permission pair; justified-broad discount applies for MediaDownloader category → -1.5.
  • install_url_hijack crx install_url_hijack=true; target null but flag present → +2.0 webstore (onInstalled opens 3rd-party URL).
  • uninstall_url_hijack crx uninstall_url_hijack=true; target null but flag present → +3.0 webstore (setUninstallURL to 3rd party).
  • gmail_developer store Developer email inb.cor@gmail.com; free webmail, no verified business domain → reputation penalty.
  • geo_diversity crx JS hosts span 4 countries (CA,IN,NL,US); category MediaDownloader does not exempt → +1.5 network.
  • no_csp manifest content_security_policy is null on MV3; MV3 strict default applies, no +2.0 MV2 penalty.
  • is_featured_by_google store Extension carries Google Featured badge → -2.0 reputation discount applied.

Permissions Breakdown

  • storage low Stores user preferences locally; minimal risk.
  • webRequest high Can intercept and observe all network requests across all URLs.
  • downloads medium Can initiate and manage file downloads.
  • notifications low Shows desktop notifications; low standalone risk.
  • contextMenus low Adds right-click menu items; low risk.
  • *://*/* high Broad host access to every HTTP/HTTPS site; amplifies webRequest risk.

Pillar Scores

Permissions6.50
Reputation6.50
Network5.50
Webstore5.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Scoring History

sssieddrubricxsx 5.39 Medium review 2026-08-13
v3.6 5.24 Medium review 2026-06-16
v3.4-rev 5.05 Medium review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:30
Listing SHA 5e461188ab39…
Force block — not fired
Score recovered no
Elapsed 22.4s