Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

GetVid - Video Downloader

hojamkafiddgonggjfbkmeollglcmjao
Risk Score
2.86
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category VideoDownloader
Installs 20,000
Rating 4.6
Last updated 2026-06-10
Manifest version MV3
CSP present ✅ yes
Developer support@getvid.site
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • cookies + <all_urls> + webRequest: full request interception and cookie access on every site visited.
  • Privacy policy lacks extension scope and retention disclosure; data_collection=true with no specificity.
  • 3 innerHTML-from-variable DOM-XSS sinks in content and background scripts injected on all URLs.
  • 12 external JS hosts including login.yahoo.com, login.live.com, login.microsoftonline.com — broad SSO-surface contact.
  • Description mismatch: promises download but lacks 'downloads' permission — functional or obfuscation concern.

Evidence

  • broad_host_permissions_with_cookies_webRequest manifest https://*/* + http://*/* host_permissions paired with cookies and webRequest — ×1.2 amplifier applied.
  • verified_publisher_featured store verified_publisher=true and is_featured_by_google=true; reputation floor applied at 2.0.
  • privacy_policy_scope_missing api Policy fetched (14478 chars), data_collection=true but scope_extension=false, retention=false → +9.0.
  • dom_xss_sinks_x3 crx dom_sink_innerhtml_userctrl in background-bundle, content-bundle, dom-inspector.js with CSP present.
  • external_hosts_12_distinct crx 12 distinct external hosts including multiple SSO/auth endpoints; >3 distinct domains → +1.5 network.
  • description_permission_mismatch store promises download but lacks 'downloads' permission per description_promise.mismatches.
  • no_cve_findings crx cve_findings_raw is empty; CVE pillar = 0.0.
  • justified_broad_category_discount manifest VideoDownloader category — -1.5 justified-broad-permission discount applied to permissions pillar.

Permissions Breakdown

  • cookies high Can read/write cookies across all sites via broad host_permissions.
  • activeTab low Scoped to user-invoked tab only; low standalone risk.
  • storage low Local extension storage only.
  • webRequest high Intercepts all HTTP/S requests across all URLs — core downloader need but high capability.
  • declarativeNetRequest medium Can modify/block network requests declaratively; lower risk than webRequestBlocking.
  • tabs medium Access to tab URLs and metadata across sessions.
  • notifications low UI notifications only; limited abuse surface.
  • offscreen low Background document for media processing; expected for video downloader.
  • unlimitedStorage low Allows large local storage; needed for media caching.
  • commands low Keyboard shortcut bindings only.
  • https://*/* http://*/* (host_permissions) high Broad host access amplifies cookies+webRequest risk across all sites.
  • content_scripts <all_urls> high Content script injected on every page; DOM XSS sinks found in code.

Pillar Scores

Permissions5.50
Reputation2.00
Network3.50
Webstore4.00
Maintenance0.00
Privacy9.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-15 14:17
Listing SHA ec7aec0398ff…
Force block — not fired
Score recovered no
Elapsed 32.6s