Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Video Downloader Plus

hkdmdpdhfaamhgaojpelccmeehpfljgf
Risk Score
2.82
Risk Level: Low
Recommendation: ✅ ALLOW
Category VideoDownloader
Installs 1,000,000
Rating 4.5
Last updated 2026-04-21 (4 months ago)
Manifest version MV3
CSP present ✅ yes
Developer support@vidow.io
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • webRequest + <all_urls>: intercepts all browser traffic across every site visited.
  • Content scripts injected on *://*/* give broad DOM access to every page.
  • Developer name absent in listing; identity relies solely on email domain vidow.io.
  • Description promises download but lacks 'downloads' permission — minor mismatch.
  • Privacy policy collects data with third-party sharing status silent (third_party_silence=true).

Evidence

  • verified_publisher + featured_by_google store Extension holds both verified publisher and Featured badges; reduces reputation risk.
  • broad_host_access_with_webRequest manifest host_permissions=[<all_urls>] combined with webRequest; justified-broad discount applied for VideoDownloader.
  • content_scripts_all_urls manifest content_scripts_matches includes *://*/* — injects on every page, wide surface.
  • cve_findings_raw_empty crx No CVEs detected in bundled libraries; CVE pillar = 0.
  • code_findings_raw_empty crx No malicious code patterns found; obfuscation_score=0.0.
  • privacy_policy_classification api Policy fetched, scoped to extension, data_collection=true, retention=true, third_party_sharing=false but third_party_silence=true.
  • description_promise_mismatch store Promises download but lacks 'downloads' permission; is_shell_pattern=false.
  • threat_intel_clean api No bad_host_hits, affiliate_hits, or monetization_hits; developer domain resolves, not throwaway.

Permissions Breakdown

  • tabs medium Can read tab URLs and metadata; needed for video detection.
  • webRequest high Intercepts all network requests; core for detecting video streams but broad capability.
  • declarativeNetRequest medium Can block/modify requests declaratively; lower risk than webRequestBlocking.
  • storage low Local state storage; minimal risk.
  • <all_urls> (host_permission) high Broad host access paired with webRequest; justified for video downloader category.
  • content_scripts *://*/* high Injects scripts on all pages; expected for video detection but wide surface.

Pillar Scores

Permissions4.50
Reputation2.00
Network2.00
Webstore3.50
Maintenance0.00
Privacy2.00
Code Quality0.00
CVE Exposure0.00

Scoring History

sssiednfd5837fedp727562726963xsx 2.39 Low allow 2026-08-27
<fsssiedxa$"sssiedx 2.82 Low review 2026-08-17
<fsssiedxa xx psssiedx 3.06 Low allow 2026-08-17
fsssiedxa<sssiedx 2.63 Low allow 2026-08-17
<fsssiedx{'sssiedx 2.63 Low allow 2026-08-15
<fsssiedx{$'sssiedx 2.40 Low allow 2026-08-15
<fsssiedxg xx psssiedx 2.59 Low allow 2026-08-15
<fsssiedxg'sssiedx 2.34 Low allow 2026-08-15
<fsssiedxg$"sssiedx 2.64 Low review 2026-08-15
&#x22;fsssiedxw"sssiedx 2.54 Low allow 2026-08-15
&#x22;fsssiedxw&#x27;sssiedx 2.85 Low review 2026-08-15
&#x22;fsssiedxw$'sssiedx 2.87 Low review 2026-08-15
<fsssiedxwfdsaxax><!--></ScRiPt>asddsssiedx 2.62 Low allow 2026-08-15
<fsssiedxw$'sssiedx 2.54 Low allow 2026-08-15
fsssiedxw<sssiedx 2.64 Low allow 2026-08-15
&#x27;fsssiedxa"sssiedx 2.09 Low review 2026-08-08
&#x27;fsssiedxa sssiedx 3.01 Low review 2026-08-08
2.60 Low allow 2026-08-08
&#x22;fsssiedxa$"sssiedx 2.74 Low review 2026-08-08
$"fsssiedxasssiedx 2.48 Low allow 2026-08-08
fsssiedxa$"sssiedx 2.22 Low allow 2026-08-08
<fsssiedxa'sssiedx 2.46 Low allow 2026-07-28
<fsssiedxi sssiedx 2.46 Low allow 2026-07-28
fsssiedx<sssiedx 2.32 Low review 2026-07-28
<fsssiedx{ sssiedx 2.34 Low allow 2026-07-28
<fsssiedx{&#x27;sssiedx 2.72 Low allow 2026-07-28
<fsssiedx{$"sssiedx 2.62 Low allow 2026-07-28
fsssiedxxfdsaxax><!--></ScRiPt>asddsssiedx 2.38 Low allow 2026-07-28
fsssiedxx sssiedx 2.55 Low allow 2026-07-28
sssieddrubricxsx 2.29 Low allow 2026-07-28
v3.6 2.82 Low allow 2026-06-16
v3.4-rev 2.34 Low allow 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:39
Listing SHA fe7c16721fe4…
Force block — not fired
Score recovered no
Elapsed 21.0s