Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Controls for Instagram Videos

eigfbedabacomcacemdnkelnlhgbiacn
Risk Score
5.56
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VideoDownloader
Installs 90,000
Rating 3.5
Last updated 2023-02-07 (42 months ago)
Manifest version MV3
CSP present ❌ no
Developer rehfeldchris@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is generic Google account policy — does not scope to this extension at all; admits data collection and 3rd-party sharing (D rule: +10.0).
  • Extension is 40 months stale (>36mo) with 100K installs — zombie fingerprint; no security updates since Feb 2023.
  • Brand impersonation: 'Instagram' mentioned without confirmed ownership, developer is unverified free-webmail account.
  • Uninstall URL hijack detected — extension registers a 3rd-party uninstall redirect.
  • innerHTML DOM-XSS sink in ic-util.js with no CSP present — exploitable if attacker controls injected HTML.

Evidence

  • privacy_policy_generic_google store Policy URL is myaccount.google.com/privacypolicy — scope_extension=false, data_collection=true, third_party_sharing=true. Rule D: +10.0.
  • stale_zombie store 40 months since last update, 100K installs. >36mo base +10.0, zombie booster +1.0 (capped at 10).
  • brand_impersonation store brand_mention.is_impersonation=true, brands=['instagram'], confirmed_owner=false. Not verified publisher for this brand.
  • uninstall_url_hijack crx uninstall_url_hijack=true — runtime.setUninstallURL to 3rd party. Webstore +3.0.
  • dom_xss_no_csp crx dom_sink_innerhtml_userctrl in ic-util.js with csp_present=false triggers FIX B: +2.0 code quality.
  • description_mismatch store Promises download but lacks 'downloads' permission. +2.0 webstore.
  • free_webmail_no_dev_name store developer_email=rehfeldchris@gmail.com, developer_name=''. Free webmail + no name floor reputation >=7.5 before discounts.
  • verified_publisher_featured_discounts_capped store verified_publisher=true, is_featured=true but months_since_update=40>18 → invariant 0c caps discount at -1.0 total.

Permissions Breakdown

  • storage low Stores local settings; no cross-site data risk on its own.
  • content_scripts: https://*.instagram.com/* medium Runs JS in Instagram pages; scoped to single domain, matches stated function.

Pillar Scores

Permissions1.30
Reputation6.50
Network2.00
Webstore5.00
Maintenance10.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Scoring History

<fsssiedxi xx psssiedx 5.44 Medium review 2026-08-17
<fsssiedxa sssiedx 5.79 Medium review 2026-08-17
fsssiedx<sssiedx 5.83 Medium review 2026-08-17
fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 5.88 Medium review 2026-08-10
fsssiedxa xx psssiedx 4.34 Medium review 2026-08-10
fsssiedxa 5.63 Medium review 2026-08-10
sssieddrubricxsx 5.57 Medium review 2026-08-10
v3.6 5.56 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:30
Listing SHA 9618f27ef7e9…
Force block — not fired
Score recovered no
Elapsed 25.0s