Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

video downloader

kaibkgfibgoffomjemobnlojipabbbjd
Risk Score
4.84
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VideoDownloader
Installs 30,000
Rating 4.4
Last updated 2025-04-21 (14 months ago)
Manifest version MV3
CSP present ✅ yes
Developer dodlailuan@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy URL unreachable (fetch error) — treated as no policy; data handling unknown.
  • webRequest + <all_urls> + scripting: can intercept and modify all browser traffic on every site.
  • Free-webmail developer (dodlailuan@gmail.com) with no verified business identity.
  • 8 external JS hosts contacted including vdrt-chromium.github.io and vidow.me — unverified third-party CDN risk.
  • dom_sink_innerhtml_userctrl in popup.js: XSS sink that could be exploited if DOM input is attacker-controlled.

Evidence

  • privacy_policy_fetch_failed api privacy_policy_classification.fetched==false due to ConnectionError; scored as +10.0 privacy pillar.
  • free_webmail_developer store Developer email dodlailuan@gmail.com; no verified business domain. Reputation floor applies.
  • broad_host_permission manifest <all_urls> host permission paired with webRequest and scripting — full-site interception capability.
  • external_hosts crx 8 external hosts including vdrt-chromium.github.io and vidow.me alongside major platforms.
  • dom_xss_sink crx innerHTML assigned from variable in popup.js; CSP present (self-only) limits but doesn't eliminate risk.
  • maintenance_stale store Last updated April 2025; months_since_update=14 → +6.0 maintenance score.
  • content_scripts_all_urls manifest Content scripts injected on <all_urls> in addition to named social platforms.
  • no_verified_publisher store verified_publisher=false, is_featured_by_google=false; no trust discount applied.

Permissions Breakdown

  • storage low Stores user preferences locally; minimal risk.
  • webRequest high Can observe all network requests across all URLs — high surveillance capability.
  • tabs medium Access to tab URLs and metadata; paired with all_urls increases risk.
  • downloads medium Can initiate and manage downloads; core to stated function.
  • scripting high Inject scripts into any page via <all_urls> host permission.
  • alarms low Scheduled background tasks; low direct harm.
  • <all_urls> high Host permission covering every site — broadest possible reach for script injection and request interception.

Pillar Scores

Permissions6.50
Reputation7.00
Network3.50
Webstore1.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:47
Listing SHA 95aab52d68de…
Force block — not fired
Score recovered no
Elapsed 23.2s