video downloader
kaibkgfibgoffomjemobnlojipabbbjd
Risk Score
4.84
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy URL unreachable (fetch error) — treated as no policy; data handling unknown.
- webRequest + <all_urls> + scripting: can intercept and modify all browser traffic on every site.
- Free-webmail developer (dodlailuan@gmail.com) with no verified business identity.
- 8 external JS hosts contacted including vdrt-chromium.github.io and vidow.me — unverified third-party CDN risk.
- dom_sink_innerhtml_userctrl in popup.js: XSS sink that could be exploited if DOM input is attacker-controlled.
Evidence
- privacy_policy_fetch_failed api privacy_policy_classification.fetched==false due to ConnectionError; scored as +10.0 privacy pillar.
- free_webmail_developer store Developer email dodlailuan@gmail.com; no verified business domain. Reputation floor applies.
- broad_host_permission manifest <all_urls> host permission paired with webRequest and scripting — full-site interception capability.
- external_hosts crx 8 external hosts including vdrt-chromium.github.io and vidow.me alongside major platforms.
- dom_xss_sink crx innerHTML assigned from variable in popup.js; CSP present (self-only) limits but doesn't eliminate risk.
- maintenance_stale store Last updated April 2025; months_since_update=14 → +6.0 maintenance score.
- content_scripts_all_urls manifest Content scripts injected on <all_urls> in addition to named social platforms.
- no_verified_publisher store verified_publisher=false, is_featured_by_google=false; no trust discount applied.
Permissions Breakdown
- storage low Stores user preferences locally; minimal risk.
- webRequest high Can observe all network requests across all URLs — high surveillance capability.
- tabs medium Access to tab URLs and metadata; paired with all_urls increases risk.
- downloads medium Can initiate and manage downloads; core to stated function.
- scripting high Inject scripts into any page via <all_urls> host permission.
- alarms low Scheduled background tasks; low direct harm.
- <all_urls> high Host permission covering every site — broadest possible reach for script injection and request interception.
Pillar Scores
Permissions6.50
Reputation7.00
Network3.50
Webstore1.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:47
Listing SHA
95aab52d68de…
Force block
— not fired
Score recovered
no
Elapsed
23.2s