Gemini All Chat Downloader
jncnfgpbecbngbcgejflppklmmhnoadp
Risk Score
4.00
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Brand impersonation: uses 'Gemini' brand name, developer is unverified gmail user with no confirmed ownership.
- Content script runs on shivvm.com (unknown third-party domain) alongside Google AI pages — unexpected scope.
- External JS host cdn.jsdelivr.net loaded by CSP whitelist; third-party CDN dependency for a downloader.
- Privacy policy on free Blogspot hosting admits data collection and third-party sharing without retention details.
- Two DOM-XSS innerHTML sinks in background.js and content.js processing chat content from Gemini sessions.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true, brands=['gemini'], confirmed_owner=false, developer on gmail.com.
- free_webmail_developer store Developer email vivekbhardwajvk2202@gmail.com; no business domain; domain_age_ct not queried (free webmail).
- unknown_third_party_content_script manifest content_scripts_matches includes https://shivvm.com/* — unrelated to stated Gemini download function.
- external_js_hosts crx js_external_hosts: aistudio.google.com, cdn.jsdelivr.net, shivvm.com — 3 distinct registrable domains.
- dom_xss_sinks crx Two innerHTML assignments from user-controlled chat variables in background.js and content.js.
- privacy_policy_inadequate store Policy on Blogspot: scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
- description_permission_mismatch store Promises download capability but lacks 'downloads' permission in manifest.
- low_rating store Rating 3.1 — below average, though match_count=0 for explicit malware reviews.
Permissions Breakdown
- activeTab low Grants access to current tab only on user action; low blast radius.
- scripting medium Can inject scripts into pages matching host permissions/content_scripts.
- content_scripts: aistudio.google.com, gemini.google.com, shivvm.com medium Runs on Google AI pages and an unknown third-party domain (shivvm.com).
Pillar Scores
Permissions1.30
Reputation8.00
Network2.00
Webstore5.50
Maintenance1.50
Privacy2.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:47
Listing SHA
316aa08ff56f…
Force block
— not fired
Score recovered
no
Elapsed
25.5s