Bulk Image Downloader
lamfengpphafgjdgacmmnpakdphmjlji
Risk Score
3.12
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Broad host access (*://*/*) + scripting enables JS injection into every visited page.
- No CSP: DOM-XSS sinks (innerHTML) in two JS files are unmitigated by any content-security-policy.
- Free-webmail developer (gmail) with no verified business identity; chinadeveloper.net domain provenance unclear.
- Privacy policy discloses third-party data sharing without specific retention scoping for this extension.
- install_url_hijack=true: onInstalled opens an external URL, low-grade redirect signal.
Evidence
- broad_host_plus_scripting manifest host_permissions=[*://*/*] + scripting permission + content_scripts on <all_urls> — full page access.
- no_csp crx content_security_policy is null; MV3 default CSP applies but no explicit restriction hardens DOM sinks.
- dom_xss_sinks crx innerHTML user-controlled sink found in 2 JS files; no CSP amplifies FIX B risk (+2.0 code quality).
- free_webmail_developer store Developer email tiger.hu.liu@gmail.com — free webmail, no verified business domain.
- verified_publisher_featured store Extension is verified_publisher=true and is_featured_by_google=true — significant trust discount applied.
- install_url_hijack crx install_url_hijack=true; target null — onInstalled opens external URL, minor monetization signal.
- privacy_policy_third_party_sharing api Policy at chinadeveloper.net/en/privacy discloses data collection + third-party sharing; retention present.
- js_external_hosts crx js_external_hosts=[reactjs.org] — CDN/doc reference only; single US-hosted endpoint, low geo diversity.
Permissions Breakdown
- downloads medium Core function — downloads files to local disk; matches MediaDownloader category.
- storage low Persists settings locally; standard low-risk use.
- contextMenus low Adds right-click UI; no data exfil path.
- tabs medium Can read tab URLs and titles across all tabs.
- scripting high Injects scripts into any page via *://*/* host permission — broad execution surface.
- *://*/* high Broad host access on all HTTP/HTTPS origins; paired with scripting amplifies risk.
- <all_urls> (content_scripts) high Content scripts run on every page; captures page DOM including sensitive data.
Pillar Scores
Permissions5.10
Reputation3.50
Network2.00
Webstore3.00
Maintenance0.00
Privacy1.00
Code Quality2.00
CVE Exposure0.00
Scoring History
| <fsssiedx{'sssiedx | 3.44 | Low | review | 2026-08-22 |
| %22fsssiedxt sssiedx | 2.68 | Low | review | 2026-08-22 |
| <fsssiedxf$"sssiedx | 2.63 | Low | review | 2026-08-22 |
| <fsssiedxa"sssiedx | 3.48 | Low | review | 2026-08-22 |
| <fsssiedxi xx psssiedx | 4.02 | Medium | review | 2026-08-22 |
| fsssiedx<sssiedx | 3.54 | Low | review | 2026-08-22 |
| fsssiedxbfdsaxax><!--></ScRiPt>asddsssiedx | 2.77 | Low | review | 2026-08-05 |
| fsssiedxb"sssiedx | 3.24 | Low | review | 2026-08-05 |
| fsssiedxb | 3.04 | Low | review | 2026-08-05 |
| sssieddrubricxsx | 3.27 | Low | review | 2026-08-05 |
| v3.6 | 3.12 | Low | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 06:26
Listing SHA
a9eca08425e4…
Force block
— not fired
Score recovered
no
Elapsed
28.3s