High Resolution Downloader for Instagram
hbijmiokbffalbolieapplfhmmnioeao
Risk Score
6.48
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Abandoned: last updated Feb 2021 (64 months ago), MV2, no CSP — high takeover/zombie risk.
- Privacy policy is Google's own generic policy (scope_extension=false, admits data collection + 3rd-party sharing) — maps to +10.0 under v3.5 rule D.
- Instagram brand impersonation by unverified gmail developer with no business presence.
- MV2 + no CSP: +2.0 network penalty; content script on instagram.com runs without sandbox.
- Description promises download but lacks 'downloads' permission — permission/function mismatch signal.
Evidence
- abandoned_extension store Last updated Feb 2021, 64 months ago; MV2; no CSP. Triple-stale fingerprint (+2.0 Webstore).
- generic_google_privacy_policy store Privacy URL is myaccount.google.com/privacypolicy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy.
- brand_impersonation store brand_mention.is_impersonation=true for 'instagram'; developer is gmail user, not Meta/Instagram → +2.0 Reputation.
- free_webmail_developer store Developer email edwin.h.morris@gmail.com; no business website; +1.5 Reputation (free-webmail, no business).
- no_csp_mv2 manifest content_security_policy=null on MV2 extension → +2.0 Network behavior.
- description_permission_mismatch store promises download but lacks 'downloads' permission per description_promise.mismatches → +2.0 Webstore.
- content_script_instagram manifest content_scripts inject into *://*.instagram.com/* with no CSP guard; can access session data.
- triple_stale_fingerprint store >24mo stale + MV2 + no CVEs (cve_findings empty) qualifies for +2.0 Webstore triple-stale rule.
Permissions Breakdown
- clipboardWrite medium Can write to clipboard; moderate misuse potential but scoped capability.
- content_scripts *://*.instagram.com/* medium Injects JS into all Instagram pages; can read page content and user data.
Pillar Scores
Permissions2.30
Reputation7.50
Network4.00
Webstore5.00
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Scoring History
| v3.6 | 6.48 | High | block | 2026-06-16 |
| v3.4-rev | 5.96 | Medium | review | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:38
Listing SHA
7310881a8067…
Force block
— not fired
Score recovered
no
Elapsed
21.0s