Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Video Downloader

jdkaphhhiagdjnojjkpknoaigekgekjh
Risk Score
6.88
Risk Level: High
Recommendation: 🚫 BLOCK
Category VideoDownloader
Installs 20,000
Rating 3.7
Last updated 2023-06-12 (36 months ago)
Manifest version MV3
CSP present ❌ no
Developer mica.muller2029@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Free-webmail developer (gmail) with no verifiable business identity; unverifiable accountability.
  • Privacy policy admits data collection and third-party sharing but is NOT scoped to this extension (references audio-editor domain).
  • Uninstall URL hijack detected; install URL hijack also present — classic monetization/tracking shell behavior.
  • 36 months without update (stale) with broad webRequest + content_scripts on all HTTPS origins still active.
  • DOM-XSS sink (innerHTML) in popup with no CSP; malicious page content could be reflected.

Evidence

  • free_webmail_developer store Developer email mica.muller2029@gmail.com; no business domain; free-webmail floor applies.
  • install_and_uninstall_url_hijack crx install_url_hijack=true and uninstall_url_hijack=true; targets not resolved but pattern is monetization-shell.
  • privacy_policy_scope_mismatch store Policy URL is audio-editor.freeonlineapps.net; scope_extension=false, data_collection=true, third_party_sharing=true.
  • stale_extension store Last updated June 2023; 36 months since update with 20,000 installs and broad host permissions still live.
  • dom_xss_sink_no_csp crx innerHTML user-controlled in popup.js; csp_present=false amplifies DOM-XSS risk.
  • broad_host_plus_webrequest manifest webRequest + https://*/* + content_scripts on all HTTP/HTTPS; HIGH×1.2 multiplier applied.
  • is_featured_by_google store Extension carries Google Featured badge, providing minor reputation credit despite gmail developer.
  • operator_dev_email_count api operator_cluster dev_email dimension count=1; no confirmed sibling extensions under same fingerprint.

Permissions Breakdown

  • webRequest high Intercept/observe all network requests across all HTTPS sites via broad host_permissions.
  • downloads medium Can initiate file downloads; core to stated function but abusable.
  • tabs medium Access to tab URLs and metadata across all open tabs.
  • https://*/* high Broad host access over all HTTPS origins; pairs with webRequest for full traffic visibility.
  • content_scripts http://*/*, https://*/* high Script injection into every page the user visits; expands attack surface significantly.

Pillar Scores

Permissions7.50
Reputation7.00
Network4.00
Webstore5.50
Maintenance8.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:45
Listing SHA 3ca74bc179b8…
Force block — not fired
Score recovered no
Elapsed 25.1s