Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Instagram Downloader - Download Reels, Story & Highlights

ekldpgadmeldbcdhehncdgdgnphmeecl
Risk Score
4.03
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category MediaDownloader
Installs 1,000
Rating 3.3
Last updated 2026-05-22 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer arianypaivadasilva94@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: uses Instagram brand, confirmed non-owner, gmail dev with no business identity.
  • Privacy policy admits data collection and third-party sharing but is NOT scoped to this extension.
  • webRequest + content_script on *.instagram.com enables interception of session tokens and user data.
  • Host permission to qooly.com (privacy policy domain) without explanation — potential data relay.
  • Verified publisher badge but developer is anonymous gmail account with no disclosed business.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true for 'instagram'; developer is gmail, confirmed_owner=false.
  • privacy_policy_scope_mismatch api Policy fetched from qooly.com; scope_extension=false, data_collection=true, third_party_sharing=true.
  • free_webmail_dev_no_business store developer_email=arianypaivadasilva94@gmail.com; developer_name empty; no business website.
  • host_permission_third_party manifest host_permissions include *://qooly.com/* alongside *.instagram.com/*; qooly.com unknown third-party.
  • function_constructor_code crx new Function() constructor found in bg.js and inject.js — dynamic code execution risk.
  • no_csp manifest content_security_policy is null; MV3 default applies but no explicit CSP declared.
  • verified_publisher_inconsistency store verified_publisher=true but dev is anonymous gmail with no name; may indicate domain-only verification.
  • tos_violation_risk store MediaDownloader scraping Instagram (major platform) — likely ToS violation per v3.5 rule 7.

Permissions Breakdown

  • storage low Stores extension state/settings locally.
  • webRequest high Can observe all network requests matching host_permissions; intercepts Instagram traffic.
  • downloads medium Can save files to user disk; core to stated function but also exfil vector.
  • *://qooly.com/* medium Grants script/webRequest access to qooly.com, an unknown third-party domain.
  • *://*.instagram.com/* high Full access to Instagram pages; can read session cookies, DOM, credentials via content script.

Pillar Scores

Permissions5.50
Reputation8.00
Network2.00
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:31
Listing SHA 75c5674c1586…
Force block — not fired
Score recovered no
Elapsed 24.7s