Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Universal Media Downloader

hnicogbjbfkjlkkeajepgjkkhojceeak
Risk Score
6.04
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category MediaDownloader
Installs 424
Rating 5.0
Last updated 2025-05-23 (13 months ago)
Manifest version MV3
CSP present ❌ no
Developer snpsujon93@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Free-webmail dev (gmail) with no verifiable business identity; low accountability.
  • Privacy policy URL returns SSL error — policy is effectively absent (fetch_error:SSLError).
  • Broad host permission + scripting + content_scripts on <all_urls> enables full page-content access on every site.
  • Claims 'download' function but lacks 'downloads' permission — description/permission mismatch is a red flag.
  • Low install count (424) with high-tier permissions raises tail-attack-surface concern.

Evidence

  • privacy_policy_fetch_failed api Privacy policy at pyd.snpsujon.me/privacy returned SSLError; treated as no fetched policy → score +10.0.
  • free_webmail_developer store Developer email snpsujon93@gmail.com with no verified business; reputation floor triggered.
  • broad_host_scripting_combo manifest host_permissions=[<all_urls>] + scripting + content_scripts on <all_urls>; full read/write on every page.
  • description_permission_mismatch store Extension promises download capability but 'downloads' permission is absent per description_promise.mismatches.
  • install_perm_anomaly api small_install_high_perm=true, tail_attack_surface=true; 424 installs with high-tier permissions.
  • external_js_host crx js_external_hosts=[pyd.snpsujon.me]; developer-controlled domain, single country (SG), no bad-host hit.
  • no_csp manifest content_security_policy is null (MV3, so no v2 penalty, but no CSP still removes hardening).
  • maintenance_6_12mo store months_since_update=13; falls in 12-24mo band → +6.0 maintenance score.

Permissions Breakdown

  • activeTab low Grants access to the current tab on user gesture only; narrow scope.
  • scripting medium Allows programmatic script injection into pages; elevated when paired with <all_urls>.
  • <all_urls> (host_permissions) high Broad host access across every site; combines with scripting for full page read/write capability.
  • <all_urls> (content_scripts_matches) high Content script runs on every URL; extends reach of any injected code to all sites.

Pillar Scores

Permissions6.50
Reputation7.00
Network2.00
Webstore6.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:40
Listing SHA c7502cff044d…
Force block — not fired
Score recovered no
Elapsed 21.6s