Video Downloader professional
knkpjhkhlfebmefnommmehegjgglnkdm
Risk Score
4.45
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- jquery@3.2.1 has 3 medium CVEs (XSS); no CSP present amplifies exploitation risk on all pages.
- webRequest + <all_urls> + content_scripts on every URL: full network interception and DOM access capability.
- Developer email is free Gmail; privacy policy hosted on Google Sites with no retention disclosure.
- 17 months since last update; jquery remains unfixed at vulnerable version 3.2.1 (fixed_in 3.5.0).
- No CSP defined (MV3); combined with vulnerable jQuery and broad host access raises injection risk.
Evidence
- 3 medium CVEs in bundled jquery@3.2.1; no CSP; CVE×1.5 amplifier applied crx CVE-2019-11358, CVE-2020-11022, CVE-2020-11023 all unfixed (current 3.2.1 < fixed_in 3.5.0)
- webRequest + <all_urls> host_permissions + content_scripts on <all_urls> manifest Triple broad-access pattern; justified-broad discount applied for VideoDownloader category.
- No content_security_policy declared (MV3 default; no CSP object in manifest) manifest csp_present=false; amplifies CVE pillar for DOM-manipulation lib per v2 ×1.5 rule.
- Developer email is free Gmail; privacy policy on Google Sites store romanfrancis9881@gmail.com; policy fetched but hosted on free platform, no retention clause.
- 9 external JS hosts including social platforms; geo-diversity 3 countries (CA, IN, US) crx api.twitter.com, player.vimeo.com, www.facebook.com etc. — 3 countries, below +1.5 threshold.
- is_featured_by_google=true; verified_publisher=false store Featured badge reduces reputation; not verified publisher so no -3.0 discount.
- 17 months since update; maintenance pillar elevated store last_updated January 24, 2025; 12-24mo band = +6.0 base, minus changelog discount not applicable.
- Privacy policy: data_collection=true, retention=false, third_party_silence=true api Scoped to extension, collects data, no retention info, silence on 3rd-party sharing adds +1.0.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@3.2.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.2.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.2.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- tabs medium Access to tab URLs/titles; needed for video detection but enables browsing surveillance.
- downloads medium Can initiate file downloads; core to stated function but could be abused for drive-by drops.
- storage low Local data persistence; low risk in isolation.
- webRequest high Intercepts all network requests across all URLs; high capability paired with <all_urls>.
- <all_urls> (host_permissions) high Broad host access enabling content scripts and webRequest on every site visited.
- <all_urls> (content_scripts_matches) high Content script injected on every page; can read/modify page DOM and data.
Pillar Scores
Permissions4.80
Reputation6.00
Network4.00
Webstore2.50
Maintenance6.00
Privacy2.00
Code Quality2.00
CVE Exposure4.50
Scoring History
| <fsssiedxa$"sssiedx | 3.47 | Low | review | 2026-08-22 |
| 'fsssiedxa xx psssiedx | 3.53 | Low | review | 2026-08-19 |
| 'fsssiedxa$'sssiedx | 3.31 | Low | review | 2026-08-19 |
| 3.55 | Low | review | 2026-08-19 | |
| $"fsssiedxasssiedx | 3.52 | Low | review | 2026-08-19 |
| fsssiedxa$"sssiedx | 3.47 | Low | review | 2026-08-19 |
| xx pfsssiedxa$'sssiedx | 4.22 | Medium | review | 2026-08-13 |
| 'fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 3.59 | Low | review | 2026-08-13 |
| fsssiedxa<sssiedx | 3.59 | Low | review | 2026-08-13 |
| sssieddrubricxsx | 4.06 | Medium | review | 2026-07-28 |
| v3.6 | 4.45 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:50
Listing SHA
4b3a9393be08…
Force block
— not fired
Score recovered
no
Elapsed
29.3s