Instagram Downloader - Download Reels, Story & Highlights
ekldpgadmeldbcdhehncdgdgnphmeecl
Risk Score
4.03
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Brand impersonation: uses Instagram brand, confirmed non-owner, gmail dev with no business identity.
- Privacy policy admits data collection and third-party sharing but is NOT scoped to this extension.
- webRequest + content_script on *.instagram.com enables interception of session tokens and user data.
- Host permission to qooly.com (privacy policy domain) without explanation — potential data relay.
- Verified publisher badge but developer is anonymous gmail account with no disclosed business.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true for 'instagram'; developer is gmail, confirmed_owner=false.
- privacy_policy_scope_mismatch api Policy fetched from qooly.com; scope_extension=false, data_collection=true, third_party_sharing=true.
- free_webmail_dev_no_business store developer_email=arianypaivadasilva94@gmail.com; developer_name empty; no business website.
- host_permission_third_party manifest host_permissions include *://qooly.com/* alongside *.instagram.com/*; qooly.com unknown third-party.
- function_constructor_code crx new Function() constructor found in bg.js and inject.js — dynamic code execution risk.
- no_csp manifest content_security_policy is null; MV3 default applies but no explicit CSP declared.
- verified_publisher_inconsistency store verified_publisher=true but dev is anonymous gmail with no name; may indicate domain-only verification.
- tos_violation_risk store MediaDownloader scraping Instagram (major platform) — likely ToS violation per v3.5 rule 7.
Permissions Breakdown
- storage low Stores extension state/settings locally.
- webRequest high Can observe all network requests matching host_permissions; intercepts Instagram traffic.
- downloads medium Can save files to user disk; core to stated function but also exfil vector.
- *://qooly.com/* medium Grants script/webRequest access to qooly.com, an unknown third-party domain.
- *://*.instagram.com/* high Full access to Instagram pages; can read session cookies, DOM, credentials via content script.
Pillar Scores
Permissions5.50
Reputation8.00
Network2.00
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:31
Listing SHA
75c5674c1586…
Force block
— not fired
Score recovered
no
Elapsed
24.7s