Video Downloader
jdkaphhhiagdjnojjkpknoaigekgekjh
Risk Score
6.88
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Free-webmail developer (gmail) with no verifiable business identity; unverifiable accountability.
- Privacy policy admits data collection and third-party sharing but is NOT scoped to this extension (references audio-editor domain).
- Uninstall URL hijack detected; install URL hijack also present — classic monetization/tracking shell behavior.
- 36 months without update (stale) with broad webRequest + content_scripts on all HTTPS origins still active.
- DOM-XSS sink (innerHTML) in popup with no CSP; malicious page content could be reflected.
Evidence
- free_webmail_developer store Developer email mica.muller2029@gmail.com; no business domain; free-webmail floor applies.
- install_and_uninstall_url_hijack crx install_url_hijack=true and uninstall_url_hijack=true; targets not resolved but pattern is monetization-shell.
- privacy_policy_scope_mismatch store Policy URL is audio-editor.freeonlineapps.net; scope_extension=false, data_collection=true, third_party_sharing=true.
- stale_extension store Last updated June 2023; 36 months since update with 20,000 installs and broad host permissions still live.
- dom_xss_sink_no_csp crx innerHTML user-controlled in popup.js; csp_present=false amplifies DOM-XSS risk.
- broad_host_plus_webrequest manifest webRequest + https://*/* + content_scripts on all HTTP/HTTPS; HIGH×1.2 multiplier applied.
- is_featured_by_google store Extension carries Google Featured badge, providing minor reputation credit despite gmail developer.
- operator_dev_email_count api operator_cluster dev_email dimension count=1; no confirmed sibling extensions under same fingerprint.
Permissions Breakdown
- webRequest high Intercept/observe all network requests across all HTTPS sites via broad host_permissions.
- downloads medium Can initiate file downloads; core to stated function but abusable.
- tabs medium Access to tab URLs and metadata across all open tabs.
- https://*/* high Broad host access over all HTTPS origins; pairs with webRequest for full traffic visibility.
- content_scripts http://*/*, https://*/* high Script injection into every page the user visits; expands attack surface significantly.
Pillar Scores
Permissions7.50
Reputation7.00
Network4.00
Webstore5.50
Maintenance8.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:45
Listing SHA
3ca74bc179b8…
Force block
— not fired
Score recovered
no
Elapsed
25.1s