Universal Media Downloader
hnicogbjbfkjlkkeajepgjkkhojceeak
Risk Score
6.04
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- Free-webmail dev (gmail) with no verifiable business identity; low accountability.
- Privacy policy URL returns SSL error — policy is effectively absent (fetch_error:SSLError).
- Broad host permission + scripting + content_scripts on <all_urls> enables full page-content access on every site.
- Claims 'download' function but lacks 'downloads' permission — description/permission mismatch is a red flag.
- Low install count (424) with high-tier permissions raises tail-attack-surface concern.
Evidence
- privacy_policy_fetch_failed api Privacy policy at pyd.snpsujon.me/privacy returned SSLError; treated as no fetched policy → score +10.0.
- free_webmail_developer store Developer email snpsujon93@gmail.com with no verified business; reputation floor triggered.
- broad_host_scripting_combo manifest host_permissions=[<all_urls>] + scripting + content_scripts on <all_urls>; full read/write on every page.
- description_permission_mismatch store Extension promises download capability but 'downloads' permission is absent per description_promise.mismatches.
- install_perm_anomaly api small_install_high_perm=true, tail_attack_surface=true; 424 installs with high-tier permissions.
- external_js_host crx js_external_hosts=[pyd.snpsujon.me]; developer-controlled domain, single country (SG), no bad-host hit.
- no_csp manifest content_security_policy is null (MV3, so no v2 penalty, but no CSP still removes hardening).
- maintenance_6_12mo store months_since_update=13; falls in 12-24mo band → +6.0 maintenance score.
Permissions Breakdown
- activeTab low Grants access to the current tab on user gesture only; narrow scope.
- scripting medium Allows programmatic script injection into pages; elevated when paired with <all_urls>.
- <all_urls> (host_permissions) high Broad host access across every site; combines with scripting for full page read/write capability.
- <all_urls> (content_scripts_matches) high Content script runs on every URL; extends reach of any injected code to all sites.
Pillar Scores
Permissions6.50
Reputation7.00
Network2.00
Webstore6.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:40
Listing SHA
c7502cff044d…
Force block
— not fired
Score recovered
no
Elapsed
21.6s