GetVid - Video Downloader
hojamkafiddgonggjfbkmeollglcmjao
Risk Score
2.86
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- cookies + <all_urls> + webRequest: full request interception and cookie access on every site visited.
- Privacy policy lacks extension scope and retention disclosure; data_collection=true with no specificity.
- 3 innerHTML-from-variable DOM-XSS sinks in content and background scripts injected on all URLs.
- 12 external JS hosts including login.yahoo.com, login.live.com, login.microsoftonline.com — broad SSO-surface contact.
- Description mismatch: promises download but lacks 'downloads' permission — functional or obfuscation concern.
Evidence
- broad_host_permissions_with_cookies_webRequest manifest https://*/* + http://*/* host_permissions paired with cookies and webRequest — ×1.2 amplifier applied.
- verified_publisher_featured store verified_publisher=true and is_featured_by_google=true; reputation floor applied at 2.0.
- privacy_policy_scope_missing api Policy fetched (14478 chars), data_collection=true but scope_extension=false, retention=false → +9.0.
- dom_xss_sinks_x3 crx dom_sink_innerhtml_userctrl in background-bundle, content-bundle, dom-inspector.js with CSP present.
- external_hosts_12_distinct crx 12 distinct external hosts including multiple SSO/auth endpoints; >3 distinct domains → +1.5 network.
- description_permission_mismatch store promises download but lacks 'downloads' permission per description_promise.mismatches.
- no_cve_findings crx cve_findings_raw is empty; CVE pillar = 0.0.
- justified_broad_category_discount manifest VideoDownloader category — -1.5 justified-broad-permission discount applied to permissions pillar.
Permissions Breakdown
- cookies high Can read/write cookies across all sites via broad host_permissions.
- activeTab low Scoped to user-invoked tab only; low standalone risk.
- storage low Local extension storage only.
- webRequest high Intercepts all HTTP/S requests across all URLs — core downloader need but high capability.
- declarativeNetRequest medium Can modify/block network requests declaratively; lower risk than webRequestBlocking.
- tabs medium Access to tab URLs and metadata across sessions.
- notifications low UI notifications only; limited abuse surface.
- offscreen low Background document for media processing; expected for video downloader.
- unlimitedStorage low Allows large local storage; needed for media caching.
- commands low Keyboard shortcut bindings only.
- https://*/* http://*/* (host_permissions) high Broad host access amplifies cookies+webRequest risk across all sites.
- content_scripts <all_urls> high Content script injected on every page; DOM XSS sinks found in code.
Pillar Scores
Permissions5.50
Reputation2.00
Network3.50
Webstore4.00
Maintenance0.00
Privacy9.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-15 14:17
Listing SHA
ec7aec0398ff…
Force block
— not fired
Score recovered
no
Elapsed
32.6s