Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

EasyLoad: Instagram Uploader & Scheduler

elnnmjddaleoeklbolbfhagpikikkkin
Risk Score
5.49
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 10,000
Rating 4.4
Last updated 2026-06-03
Manifest version MV3
CSP present ✅ yes
Developer luisvallison@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • cookies + webRequest + full Instagram host access = session-hijack capability for gmail-only dev with no scoped privacy policy
  • Privacy policy is Google's generic account policy (scope_extension=false, data_collection=true, third_party_sharing=true) — scores maximum 10.0
  • Brand impersonation: confirmed Instagram branding, developer is unverified gmail account 'BestApp_4You'
  • declarativeNetRequestWithHostAccess on Instagram/CDN can silently rewrite or block API requests
  • Free-webmail developer with no verified business domain; no accountability anchor if extension is sold or compromised

Evidence

  • cookies+webRequest+host_permissions manifest cookies + webRequest + https://*.instagram.com/* enables full Instagram session token access.
  • brand_impersonation store brand_mention.is_impersonation=true for 'instagram'; confirmed_owner=false; dev is gmail.
  • generic_privacy_policy api Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • free_webmail_dev store Developer email luisvallison@gmail.com; no verified publisher; no business domain.
  • is_featured_by_google store Extension carries Google Featured badge; partially offsets reputation penalty.
  • declarativeNetRequestWithHostAccess manifest Can rewrite network requests to Instagram/CDN; high-capability permission for an uploader tool.
  • external_js_hosts crx Loads from cdn.jsdelivr.net and emscripten.org; CSP allows wasm-unsafe-eval for WASM use.
  • no_bad_hosts_no_cve api bad_host_hits=[], affiliate_hits=[], monetization_hits=[], cve_findings_raw=[] — no active malicious signals.

Permissions Breakdown

  • tabs medium Can enumerate open tabs and URLs; medium risk on its own.
  • storage low Local key-value storage; low standalone risk.
  • alarms low Scheduling alarms; needed for upload scheduler feature.
  • webRequest high Can observe all network requests to host_permissions URLs including auth cookies.
  • cookies high Paired with Instagram host access — can read session cookies; high exfil risk.
  • declarativeNetRequestWithHostAccess high Can rewrite/block requests to Instagram/CDN domains; broad manipulation capability.
  • unlimitedStorage low Allows unbounded local storage; low risk alone.
  • offscreen medium Hidden document execution context; can be abused for stealthy processing.
  • https://*.cdninstagram.com/* high Host access to Instagram CDN; paired with cookies creates session-hijack surface.
  • https://*.instagram.com/* high Full host access to Instagram including auth endpoints; combined with cookies is critical.
  • https://*.fbcdn.net/* high Facebook CDN access; broadens surface beyond stated Instagram-only purpose.

Pillar Scores

Permissions7.50
Reputation7.50
Network2.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:31
Listing SHA df96090bbb29…
Force block — not fired
Score recovered no
Elapsed 26.6s