Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Video Downloader professional

knkpjhkhlfebmefnommmehegjgglnkdm
Risk Score
4.45
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VideoDownloader
Installs 100,000
Rating 3.6
Last updated 2026-08-01
Manifest version MV3
CSP present ❌ no
Developer romanfrancis9881@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • jquery@3.2.1 has 3 medium CVEs (XSS); no CSP present amplifies exploitation risk on all pages.
  • webRequest + <all_urls> + content_scripts on every URL: full network interception and DOM access capability.
  • Developer email is free Gmail; privacy policy hosted on Google Sites with no retention disclosure.
  • 17 months since last update; jquery remains unfixed at vulnerable version 3.2.1 (fixed_in 3.5.0).
  • No CSP defined (MV3); combined with vulnerable jQuery and broad host access raises injection risk.

Evidence

  • 3 medium CVEs in bundled jquery@3.2.1; no CSP; CVE×1.5 amplifier applied crx CVE-2019-11358, CVE-2020-11022, CVE-2020-11023 all unfixed (current 3.2.1 < fixed_in 3.5.0)
  • webRequest + <all_urls> host_permissions + content_scripts on <all_urls> manifest Triple broad-access pattern; justified-broad discount applied for VideoDownloader category.
  • No content_security_policy declared (MV3 default; no CSP object in manifest) manifest csp_present=false; amplifies CVE pillar for DOM-manipulation lib per v2 ×1.5 rule.
  • Developer email is free Gmail; privacy policy on Google Sites store romanfrancis9881@gmail.com; policy fetched but hosted on free platform, no retention clause.
  • 9 external JS hosts including social platforms; geo-diversity 3 countries (CA, IN, US) crx api.twitter.com, player.vimeo.com, www.facebook.com etc. — 3 countries, below +1.5 threshold.
  • is_featured_by_google=true; verified_publisher=false store Featured badge reduces reputation; not verified publisher so no -3.0 discount.
  • 17 months since update; maintenance pillar elevated store last_updated January 24, 2025; 12-24mo band = +6.0 base, minus changelog discount not applicable.
  • Privacy policy: data_collection=true, retention=false, third_party_silence=true api Scoped to extension, collects data, no retention info, silence on 3rd-party sharing adds +1.0.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@3.2.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.2.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.2.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • tabs medium Access to tab URLs/titles; needed for video detection but enables browsing surveillance.
  • downloads medium Can initiate file downloads; core to stated function but could be abused for drive-by drops.
  • storage low Local data persistence; low risk in isolation.
  • webRequest high Intercepts all network requests across all URLs; high capability paired with <all_urls>.
  • <all_urls> (host_permissions) high Broad host access enabling content scripts and webRequest on every site visited.
  • <all_urls> (content_scripts_matches) high Content script injected on every page; can read/modify page DOM and data.

Pillar Scores

Permissions4.80
Reputation6.00
Network4.00
Webstore2.50
Maintenance6.00
Privacy2.00
Code Quality2.00
CVE Exposure4.50

Scoring History

<fsssiedxa$"sssiedx 3.47 Low review 2026-08-22
&#x27;fsssiedxa xx psssiedx 3.53 Low review 2026-08-19
&#x27;fsssiedxa$'sssiedx 3.31 Low review 2026-08-19
3.55 Low review 2026-08-19
$"fsssiedxasssiedx 3.52 Low review 2026-08-19
fsssiedxa$"sssiedx 3.47 Low review 2026-08-19
xx pfsssiedxa$'sssiedx 4.22 Medium review 2026-08-13
&#x27;fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 3.59 Low review 2026-08-13
fsssiedxa<sssiedx 3.59 Low review 2026-08-13
sssieddrubricxsx 4.06 Medium review 2026-07-28
v3.6 4.45 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:50
Listing SHA 4b3a9393be08…
Force block — not fired
Score recovered no
Elapsed 29.3s