Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Video Downloader Pro

hebjaboacandjnlnhocfikmaghgbfjlp
Risk Score
3.35
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category VideoDownloader
Installs 100,000
Rating 4.3
Last updated 2026-01-18 (8 months ago)
Manifest version MV3
CSP present ❌ no
Developer santosewilliames841@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Free-webmail dev (gmail) with no developer name raises accountability concern.
  • webRequest + scripting + <all_urls>: full read/intercept capability on every site visited.
  • No CSP: DOM-XSS sink (innerHTML) in popup.js has no mitigating policy.
  • Privacy policy present but lacks data retention disclosure and third-party sharing is silent.
  • Verified publisher / featured badges mitigate but do not eliminate broad-capability risk.

Evidence

  • free_webmail_developer store Developer email santosewilliames841@gmail.com with no developer name and no verified business.
  • broad_host_access manifest <all_urls> in host_permissions and content_scripts_matches; paired with webRequest and scripting.
  • no_csp crx content_security_policy is null; no CSP present for MV3 extension.
  • dom_xss_sink crx innerHTML used on variable in scripts/popup.js without CSP or sanitisation — DOM-XSS risk.
  • verified_and_featured store verified_publisher=true and is_featured_by_google=true; applied Reputation discounts.
  • privacy_policy_gaps api Policy scoped to extension, data_collection=true, but retention=false and third_party_silence=true.
  • js_external_hosts crx External hosts listed: api.x.com, jquery.com, reactjs.org (6 domains); 2 countries CA/US.
  • maintenance_recent store Last updated January 18, 2026 (5 months ago); 3-6mo band applies (+1.5).

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2012-6708 jquery@unknown moderate 1.9.0 Cross-Site Scripting in jquery
CVE-2011-4969 jquery@unknown moderate 1.6.3 jQuery vulnerable to Cross-Site Scripting (XSS)
CVE-2015-9251 jquery@unknown moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • downloads medium Can save files to disk; fits VideoDownloader category.
  • storage low Local extension storage only.
  • webRequest high Can observe all network traffic across all URLs; paired with <all_urls>.
  • tabs medium Can read tab URLs and metadata.
  • scripting high Can inject JS into any page; paired with <all_urls> host permission.
  • <all_urls> (host_permission) high Broad host access amplifies webRequest and scripting risk across every site.
  • <all_urls> (content_scripts) high Content script injected on every page; -1.5 justified-broad discount applied for VideoDownloader.

Pillar Scores

Permissions5.50
Reputation6.50
Network2.00
Webstore2.50
Maintenance1.50
Privacy2.00
Code Quality2.00
CVE Exposure0.00

Scoring History

sssiedn73d10c83dp727562726963xsx 5.17 Medium review 2026-09-07
v3.6 3.35 Low review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:38
Listing SHA 586d67d0ab38…
Force block — not fired
Score recovered no
Elapsed 24.3s