InLoad - App Client for Instagram
ikcgnmhndofpnljaijlpjjbbpiamehan
Risk Score
4.79
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Instagram brand impersonation by Gmail developer with no verified business identity.
- jquery@2.2.4 bundles 4 moderate XSS CVEs (none fixed); no CSP amplifies DOM-sink risk.
- content_scripts declare <all_urls> far beyond stated instagram.com scope — broad page access.
- Privacy policy lacks data retention disclosure and third-party sharing status unclear.
- Verified publisher + Gmail dev email + no developer name is weak accountability for 50K users.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true for 'instagram'; developer is nicollezindes@gmail.com, confirmed_owner=false.
- free_webmail_dev_no_name store developer_name is empty; developer_email is gmail.com; no verified business domain.
- cve_moderate_x4_jquery crx jquery@2.2.4 has CVE-2019-11358, CVE-2020-11022, CVE-2020-11023, CVE-2015-9251; fixed_in 3.4.0/3.5.0.
- no_csp_with_cve_dom_lib crx csp_present=false combined with vulnerable jQuery triggers v2e +2.0 code quality amplifier.
- host_permissions_all_urls manifest host_permissions includes <all_urls> and content_scripts_matches includes <all_urls>, beyond instagram.com.
- privacy_policy_no_retention store Privacy policy fetched, scope_extension=true, data_collection=true, but retention=false; third_party_silence=true.
- verified_publisher_gmail store verified_publisher=true but developer email is Gmail with no developer domain; 0c cap may apply.
- js_external_hosts crx 5 external hosts referenced: chrome.google.com, jquery.com, jquery.org, sizzlejs.com, www.instagram.com.
CVE Exposures (4)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@2.2.4 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@2.2.4 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@2.2.4 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@2.2.4 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- storage low Local extension data only; standard low risk.
- downloads medium Can initiate file downloads to user's disk; fits MediaDownloader but medium risk.
- system.display low Read display configuration; low impact.
- declarativeNetRequest medium Can modify/block network requests declaratively; notable capability.
- <all_urls> (host_permission) high Content scripts injected on all URLs expands attack surface far beyond instagram.com.
Pillar Scores
Permissions5.50
Reputation7.50
Network3.50
Webstore4.50
Maintenance1.50
Privacy2.00
Code Quality2.00
CVE Exposure5.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:44
Listing SHA
8d7c7f992fac…
Force block
— not fired
Score recovered
no
Elapsed
26.7s