Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

InLoad - App Client for Instagram

ikcgnmhndofpnljaijlpjjbbpiamehan
Risk Score
4.79
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category MediaDownloader
Installs 50,000
Rating 4.6
Last updated 2025-11-03 (7 months ago)
Manifest version MV3
CSP present ❌ no
Developer nicollezindes@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Instagram brand impersonation by Gmail developer with no verified business identity.
  • jquery@2.2.4 bundles 4 moderate XSS CVEs (none fixed); no CSP amplifies DOM-sink risk.
  • content_scripts declare <all_urls> far beyond stated instagram.com scope — broad page access.
  • Privacy policy lacks data retention disclosure and third-party sharing status unclear.
  • Verified publisher + Gmail dev email + no developer name is weak accountability for 50K users.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true for 'instagram'; developer is nicollezindes@gmail.com, confirmed_owner=false.
  • free_webmail_dev_no_name store developer_name is empty; developer_email is gmail.com; no verified business domain.
  • cve_moderate_x4_jquery crx jquery@2.2.4 has CVE-2019-11358, CVE-2020-11022, CVE-2020-11023, CVE-2015-9251; fixed_in 3.4.0/3.5.0.
  • no_csp_with_cve_dom_lib crx csp_present=false combined with vulnerable jQuery triggers v2e +2.0 code quality amplifier.
  • host_permissions_all_urls manifest host_permissions includes <all_urls> and content_scripts_matches includes <all_urls>, beyond instagram.com.
  • privacy_policy_no_retention store Privacy policy fetched, scope_extension=true, data_collection=true, but retention=false; third_party_silence=true.
  • verified_publisher_gmail store verified_publisher=true but developer email is Gmail with no developer domain; 0c cap may apply.
  • js_external_hosts crx 5 external hosts referenced: chrome.google.com, jquery.com, jquery.org, sizzlejs.com, www.instagram.com.

CVE Exposures (4)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@2.2.4 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@2.2.4 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@2.2.4 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@2.2.4 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • storage low Local extension data only; standard low risk.
  • downloads medium Can initiate file downloads to user's disk; fits MediaDownloader but medium risk.
  • system.display low Read display configuration; low impact.
  • declarativeNetRequest medium Can modify/block network requests declaratively; notable capability.
  • <all_urls> (host_permission) high Content scripts injected on all URLs expands attack surface far beyond instagram.com.

Pillar Scores

Permissions5.50
Reputation7.50
Network3.50
Webstore4.50
Maintenance1.50
Privacy2.00
Code Quality2.00
CVE Exposure5.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:44
Listing SHA 8d7c7f992fac…
Force block — not fired
Score recovered no
Elapsed 26.7s