Image Downloader - Image Search
jfafkhnopckjfmnpekbmpmghhdlijaja
Risk Score
4.93
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Free-webmail developer (gmail) with no verified business identity raises accountability gap.
- Privacy policy hosted on Google Sites, not scoped to this extension; data_collection=true, retention undisclosed.
- webRequest + <all_urls> content scripts enable broad passive observation of all browsing traffic.
- innerHTML sinks in popup.js and contentScript.js create DOM-XSS exposure on every visited page.
- Stale 17 months; no verified publisher; policy admits data collection without scope or retention terms.
Evidence
- free_webmail_developer store Developer email is thinhkifaresduc@gmail.com — no verified business domain.
- broad_host_permissions manifest <all_urls> host_permissions + content_scripts_matches on all URLs; paired with webRequest.
- privacy_policy_not_scoped api Policy on Google Sites; scope_extension=false, data_collection=true, retention=false, third_party_silence=true.
- dom_xss_sinks crx innerHTML assigned from variable in both popup.js and contentScript.js (React internals pattern but present in content script).
- maintenance_stale store Last updated January 19 2025; 17 months since update — approaching high-risk threshold.
- featured_by_google store is_featured_by_google=true provides moderate trust signal.
- no_bad_hosts_or_affiliates api bad_host_hits, affiliate_hits, monetization_hits all empty; 1 external host reactjs.org (CDN reference only).
- cve_clean crx cve_findings_raw is empty; no bundled vulnerable libraries detected.
Permissions Breakdown
- storage low Saves extension settings locally.
- activeTab low Temporary access to current tab on user action.
- scripting medium Can inject scripts into pages; combined with <all_urls> broadens reach.
- downloads medium Core to stated function; can download arbitrary files.
- webRequest high Can observe all HTTP requests across all URLs.
- declarativeNetRequest medium Can block/redirect network requests declaratively.
- sidePanel low UI surface only; low standalone risk.
- <all_urls> high Broad host access enables content scripts and requests on every site.
Pillar Scores
Permissions5.50
Reputation6.50
Network2.00
Webstore1.00
Maintenance6.00
Privacy9.00
Code Quality1.00
CVE Exposure0.00
Scoring History
| fsssiedxn3a14b685zan3a14b685zsssiedx | 5.44 | Medium | review | 2026-09-15 |
| sssiedn3c30cfa4dp727562726963xsx | 4.84 | Medium | review | 2026-09-15 |
| v3.6 | 4.93 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:45
Listing SHA
989acd4aaade…
Force block
— not fired
Score recovered
no
Elapsed
24.1s