Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Bulk Image Downloader

facoldpeadablbngjnohbmgaehknhcaj
Risk Score
6.08
Risk Level: High
Recommendation: 🚫 BLOCK
Category MediaDownloader
Installs 60,000
Rating 3.5
Last updated 2024-02-27 (28 months ago)
Manifest version MV3
CSP present ❌ no
Developer webmaster@antibody-software.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • nativeMessaging to unrecognized publisher — full OS code execution capability with no accountability verification.
  • Broad host_permissions (all URLs) + scripting on MV3 with no CSP — can read/modify every page visited.
  • Privacy policy fetched but lacks extension scope and omits retention; data_collection=true with third_party_silence.
  • Extension stale 28 months (>24mo band); high-capability extension not maintained raises supply-chain risk.
  • Install URL hijack to bulkimagedownloader.com?ref=chromeext466 — referral monetization on every install.

Evidence

  • nativeMessaging_unrecognized_publisher crx native_messaging_check.publisher_recognized=false; extension bridges to Windows companion app with no verified publisher identity.
  • broad_host_permissions_plus_scripting manifest host_permissions=[http://*/*, https://*/*] combined with scripting permission; no CSP present.
  • install_url_hijack crx onInstalled opens https://bulkimagedownloader.com?ref=chromeext466 — affiliate/referral redirect on every install.
  • stale_maintenance store last_updated=Feb 2024; months_since_update=28 — falls in 24-36mo band (+8.5).
  • privacy_policy_inadequate api Policy fetched; scope_extension=false, retention=false, third_party_silence=true → +9.0 privacy pillar.
  • no_developer_name store developer_name is empty string; only email webmaster@antibody-software.com available.
  • description_permission_mismatch store Promises download functionality but lacks 'downloads' permission; uses nativeMessaging instead.
  • rating_below_4 store Rating 3.5 on 60,000-install extension; no review red flags detected but mediocre satisfaction signal.

Permissions Breakdown

  • nativeMessaging high Bridges to OS-level companion app; publisher not recognized — arbitrary native code execution risk.
  • scripting high Programmatic script injection into pages; combined with broad host_permissions covers all sites.
  • http://*/* high Broad host access over all HTTP sites amplifies scripting and nativeMessaging reach.
  • https://*/* high Broad host access over all HTTPS sites; pairs with scripting for full-page read/write.
  • contextMenus low UI-only surface; low standalone risk.
  • storage low Local extension storage only; low standalone risk.

Pillar Scores

Permissions7.50
Reputation5.50
Network2.00
Webstore5.50
Maintenance8.50
Privacy9.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:32
Listing SHA 2d7827c7b6fa…
Force block — not fired
Score recovered no
Elapsed 22.2s