Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

High Resolution Downloader for Instagram

hbijmiokbffalbolieapplfhmmnioeao
Risk Score
6.48
Risk Level: High
Recommendation: 🚫 BLOCK
Category MediaDownloader
Installs 10,000
Rating 3.9
Last updated 2021-02-14 (64 months ago)
Manifest version MV2
CSP present ❌ no
Developer edwin.h.morris@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Abandoned: last updated Feb 2021 (64 months ago), MV2, no CSP — high takeover/zombie risk.
  • Privacy policy is Google's own generic policy (scope_extension=false, admits data collection + 3rd-party sharing) — maps to +10.0 under v3.5 rule D.
  • Instagram brand impersonation by unverified gmail developer with no business presence.
  • MV2 + no CSP: +2.0 network penalty; content script on instagram.com runs without sandbox.
  • Description promises download but lacks 'downloads' permission — permission/function mismatch signal.

Evidence

  • abandoned_extension store Last updated Feb 2021, 64 months ago; MV2; no CSP. Triple-stale fingerprint (+2.0 Webstore).
  • generic_google_privacy_policy store Privacy URL is myaccount.google.com/privacypolicy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy.
  • brand_impersonation store brand_mention.is_impersonation=true for 'instagram'; developer is gmail user, not Meta/Instagram → +2.0 Reputation.
  • free_webmail_developer store Developer email edwin.h.morris@gmail.com; no business website; +1.5 Reputation (free-webmail, no business).
  • no_csp_mv2 manifest content_security_policy=null on MV2 extension → +2.0 Network behavior.
  • description_permission_mismatch store promises download but lacks 'downloads' permission per description_promise.mismatches → +2.0 Webstore.
  • content_script_instagram manifest content_scripts inject into *://*.instagram.com/* with no CSP guard; can access session data.
  • triple_stale_fingerprint store >24mo stale + MV2 + no CVEs (cve_findings empty) qualifies for +2.0 Webstore triple-stale rule.

Permissions Breakdown

  • clipboardWrite medium Can write to clipboard; moderate misuse potential but scoped capability.
  • content_scripts *://*.instagram.com/* medium Injects JS into all Instagram pages; can read page content and user data.

Pillar Scores

Permissions2.30
Reputation7.50
Network4.00
Webstore5.00
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Scoring History

v3.6 6.48 High block 2026-06-16
v3.4-rev 5.96 Medium review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:38
Listing SHA 7310881a8067…
Force block — not fired
Score recovered no
Elapsed 21.0s