Mass Downloader for Instagram – Safe Bulk Download
ijcemfcomjlamigapfebkgdgehbmjpjj
Risk Score
4.56
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Instagram brand impersonation: dev is gmail-only, confirmed_owner=false, capturing Instagram session cookies.
- cookies + webRequest on instagram.com enables Instagram session credential harvesting.
- No CSP and 3x innerHTML DOM-XSS sinks across content script, options, and popup.
- Privacy policy admits data collection and third-party sharing without retention disclosure.
- Free-webmail developer (gmail) with no verifiable business identity.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true, confirmed_owner=false, developer_email is gmail; extension accesses instagram.com.
- free_webmail_dev store developer_email=bigbeatricemelo@gmail.com; no business domain; verified_publisher=true but gmail-only identity.
- high_risk_permissions_combo manifest cookies + webRequest + host_permissions instagram.com: session credential read/exfil capability.
- no_csp crx content_security_policy=null on MV3 extension; DOM-XSS sinks present in 3 JS files.
- dom_xss_sinks crx dom_sink_innerhtml_userctrl in 3 files (overlay, options, popup) with no CSP guard.
- privacy_policy_gaps api Policy fetched; scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
- igmate_backend_hosts manifest host_permissions include igmate.net and igmate.me; same domain as privacy policy; potential data exfil endpoints.
- verified_publisher_caveat store verified_publisher=true but v3.5(E) caps discount: monetization/affiliate hits absent but gmail identity undermines trust.
Permissions Breakdown
- storage low Standard local state storage; low risk.
- alarms low Scheduling only; low risk.
- downloads medium Can save files to user's disk; matches downloader category.
- cookies high Can read/write cookies for instagram.com and igmate domains; session-theft risk.
- webRequest high Observe all matching requests; combined with cookies raises credential exfil risk.
- https://*.instagram.com/* high Full access to Instagram pages; combined with cookies+webRequest = high-value session surface.
- https://igmate.net/* medium Dev-controlled backend; data may be sent there.
- https://igmate.me/* medium Second dev-controlled domain; expands exfil surface.
Pillar Scores
Permissions6.00
Reputation7.50
Network2.00
Webstore5.00
Maintenance0.00
Privacy2.00
Code Quality4.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 06:20
Listing SHA
05fa1f33cc32…
Force block
— not fired
Score recovered
no
Elapsed
27.5s