Controls for Instagram Videos
eigfbedabacomcacemdnkelnlhgbiacn
Risk Score
5.56
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is generic Google account policy — does not scope to this extension at all; admits data collection and 3rd-party sharing (D rule: +10.0).
- Extension is 40 months stale (>36mo) with 100K installs — zombie fingerprint; no security updates since Feb 2023.
- Brand impersonation: 'Instagram' mentioned without confirmed ownership, developer is unverified free-webmail account.
- Uninstall URL hijack detected — extension registers a 3rd-party uninstall redirect.
- innerHTML DOM-XSS sink in ic-util.js with no CSP present — exploitable if attacker controls injected HTML.
Evidence
- privacy_policy_generic_google store Policy URL is myaccount.google.com/privacypolicy — scope_extension=false, data_collection=true, third_party_sharing=true. Rule D: +10.0.
- stale_zombie store 40 months since last update, 100K installs. >36mo base +10.0, zombie booster +1.0 (capped at 10).
- brand_impersonation store brand_mention.is_impersonation=true, brands=['instagram'], confirmed_owner=false. Not verified publisher for this brand.
- uninstall_url_hijack crx uninstall_url_hijack=true — runtime.setUninstallURL to 3rd party. Webstore +3.0.
- dom_xss_no_csp crx dom_sink_innerhtml_userctrl in ic-util.js with csp_present=false triggers FIX B: +2.0 code quality.
- description_mismatch store Promises download but lacks 'downloads' permission. +2.0 webstore.
- free_webmail_no_dev_name store developer_email=rehfeldchris@gmail.com, developer_name=''. Free webmail + no name floor reputation >=7.5 before discounts.
- verified_publisher_featured_discounts_capped store verified_publisher=true, is_featured=true but months_since_update=40>18 → invariant 0c caps discount at -1.0 total.
Permissions Breakdown
- storage low Stores local settings; no cross-site data risk on its own.
- content_scripts: https://*.instagram.com/* medium Runs JS in Instagram pages; scoped to single domain, matches stated function.
Pillar Scores
Permissions1.30
Reputation6.50
Network2.00
Webstore5.00
Maintenance10.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Scoring History
| <fsssiedxi xx psssiedx | 5.44 | Medium | review | 2026-08-17 |
| <fsssiedxa sssiedx | 5.79 | Medium | review | 2026-08-17 |
| fsssiedx<sssiedx | 5.83 | Medium | review | 2026-08-17 |
| fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 5.88 | Medium | review | 2026-08-10 |
| fsssiedxa xx psssiedx | 4.34 | Medium | review | 2026-08-10 |
| fsssiedxa | 5.63 | Medium | review | 2026-08-10 |
| sssieddrubricxsx | 5.57 | Medium | review | 2026-08-10 |
| v3.6 | 5.56 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:30
Listing SHA
9618f27ef7e9…
Force block
— not fired
Score recovered
no
Elapsed
25.0s