Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Bulk Image Downloader

lamfengpphafgjdgacmmnpakdphmjlji
Risk Score
3.12
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category MediaDownloader
Installs 90,000
Rating 4.1
Last updated 2026-08-14
Manifest version MV3
CSP present ❌ no
Developer support@xeviora.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Broad host access (*://*/*) + scripting enables JS injection into every visited page.
  • No CSP: DOM-XSS sinks (innerHTML) in two JS files are unmitigated by any content-security-policy.
  • Free-webmail developer (gmail) with no verified business identity; chinadeveloper.net domain provenance unclear.
  • Privacy policy discloses third-party data sharing without specific retention scoping for this extension.
  • install_url_hijack=true: onInstalled opens an external URL, low-grade redirect signal.

Evidence

  • broad_host_plus_scripting manifest host_permissions=[*://*/*] + scripting permission + content_scripts on <all_urls> — full page access.
  • no_csp crx content_security_policy is null; MV3 default CSP applies but no explicit restriction hardens DOM sinks.
  • dom_xss_sinks crx innerHTML user-controlled sink found in 2 JS files; no CSP amplifies FIX B risk (+2.0 code quality).
  • free_webmail_developer store Developer email tiger.hu.liu@gmail.com — free webmail, no verified business domain.
  • verified_publisher_featured store Extension is verified_publisher=true and is_featured_by_google=true — significant trust discount applied.
  • install_url_hijack crx install_url_hijack=true; target null — onInstalled opens external URL, minor monetization signal.
  • privacy_policy_third_party_sharing api Policy at chinadeveloper.net/en/privacy discloses data collection + third-party sharing; retention present.
  • js_external_hosts crx js_external_hosts=[reactjs.org] — CDN/doc reference only; single US-hosted endpoint, low geo diversity.

Permissions Breakdown

  • downloads medium Core function — downloads files to local disk; matches MediaDownloader category.
  • storage low Persists settings locally; standard low-risk use.
  • contextMenus low Adds right-click UI; no data exfil path.
  • tabs medium Can read tab URLs and titles across all tabs.
  • scripting high Injects scripts into any page via *://*/* host permission — broad execution surface.
  • *://*/* high Broad host access on all HTTP/HTTPS origins; paired with scripting amplifies risk.
  • <all_urls> (content_scripts) high Content scripts run on every page; captures page DOM including sensitive data.

Pillar Scores

Permissions5.10
Reputation3.50
Network2.00
Webstore3.00
Maintenance0.00
Privacy1.00
Code Quality2.00
CVE Exposure0.00

Scoring History

<fsssiedx{'sssiedx 3.44 Low review 2026-08-22
%22fsssiedxt sssiedx 2.68 Low review 2026-08-22
<fsssiedxf$"sssiedx 2.63 Low review 2026-08-22
<fsssiedxa&#x22;sssiedx 3.48 Low review 2026-08-22
<fsssiedxi xx psssiedx 4.02 Medium review 2026-08-22
fsssiedx<sssiedx 3.54 Low review 2026-08-22
fsssiedxbfdsaxax><!--></ScRiPt>asddsssiedx 2.77 Low review 2026-08-05
fsssiedxb"sssiedx 3.24 Low review 2026-08-05
fsssiedxb 3.04 Low review 2026-08-05
sssieddrubricxsx 3.27 Low review 2026-08-05
v3.6 3.12 Low review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 06:26
Listing SHA a9eca08425e4…
Force block — not fired
Score recovered no
Elapsed 28.3s