EasyLoad: Instagram Uploader & Scheduler
elnnmjddaleoeklbolbfhagpikikkkin
Risk Score
5.49
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- cookies + webRequest + full Instagram host access = session-hijack capability for gmail-only dev with no scoped privacy policy
- Privacy policy is Google's generic account policy (scope_extension=false, data_collection=true, third_party_sharing=true) — scores maximum 10.0
- Brand impersonation: confirmed Instagram branding, developer is unverified gmail account 'BestApp_4You'
- declarativeNetRequestWithHostAccess on Instagram/CDN can silently rewrite or block API requests
- Free-webmail developer with no verified business domain; no accountability anchor if extension is sold or compromised
Evidence
- cookies+webRequest+host_permissions manifest cookies + webRequest + https://*.instagram.com/* enables full Instagram session token access.
- brand_impersonation store brand_mention.is_impersonation=true for 'instagram'; confirmed_owner=false; dev is gmail.
- generic_privacy_policy api Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- free_webmail_dev store Developer email luisvallison@gmail.com; no verified publisher; no business domain.
- is_featured_by_google store Extension carries Google Featured badge; partially offsets reputation penalty.
- declarativeNetRequestWithHostAccess manifest Can rewrite network requests to Instagram/CDN; high-capability permission for an uploader tool.
- external_js_hosts crx Loads from cdn.jsdelivr.net and emscripten.org; CSP allows wasm-unsafe-eval for WASM use.
- no_bad_hosts_no_cve api bad_host_hits=[], affiliate_hits=[], monetization_hits=[], cve_findings_raw=[] — no active malicious signals.
Permissions Breakdown
- tabs medium Can enumerate open tabs and URLs; medium risk on its own.
- storage low Local key-value storage; low standalone risk.
- alarms low Scheduling alarms; needed for upload scheduler feature.
- webRequest high Can observe all network requests to host_permissions URLs including auth cookies.
- cookies high Paired with Instagram host access — can read session cookies; high exfil risk.
- declarativeNetRequestWithHostAccess high Can rewrite/block requests to Instagram/CDN domains; broad manipulation capability.
- unlimitedStorage low Allows unbounded local storage; low risk alone.
- offscreen medium Hidden document execution context; can be abused for stealthy processing.
- https://*.cdninstagram.com/* high Host access to Instagram CDN; paired with cookies creates session-hijack surface.
- https://*.instagram.com/* high Full host access to Instagram including auth endpoints; combined with cookies is critical.
- https://*.fbcdn.net/* high Facebook CDN access; broadens surface beyond stated Instagram-only purpose.
Pillar Scores
Permissions7.50
Reputation7.50
Network2.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:31
Listing SHA
df96090bbb29…
Force block
— not fired
Score recovered
no
Elapsed
26.6s