Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

YT Transcript Downloader

liakknlpjigmkploknohgomhgaenjpom
Risk Score
5.17
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category MediaDownloader
Installs 7,000
Rating 3.0
Last updated 2023-11-30
Manifest version MV3
CSP present ❌ no
Developer mizanrifat001@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's own generic policy — not scoped to this extension; admits data collection and 3rd-party sharing (+10.0 privacy).
  • YouTube brand impersonation by unverified free-webmail developer (mizanrifat001@gmail.com) with no business domain.
  • Generic Google privacy policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true → worst-case privacy signal.
  • DOM-XSS sink (innerHTML) in content_script.js with no CSP present — elevated injection risk on YouTube pages.
  • No CSP on MV3 extension; stale ~18 months; promises 'download' but lacks 'downloads' permission — description mismatch.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true, brands_mentioned=['youtube'], confirmed_owner=false, dev on gmail.com.
  • free_webmail_developer manifest developer_email=mizanrifat001@gmail.com; no business domain; free-webmail fingerprint.
  • generic_google_privacy_policy store Privacy URL is myaccount.google.com/privacypolicy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • dom_xss_sink_no_csp crx innerHTML assigned from variable in content_script.js; csp_present=false; no mitigation in place.
  • description_permission_mismatch store Promises 'download' but lacks 'downloads' permission per description_promise.mismatches.
  • maintenance_stale store Last updated November 30 2023; ~18 months since update; maps to 6-12mo band (+3.5).
  • no_csp_mv3 manifest content_security_policy=null; MV3 has strict default but explicit CSP absent; +2.0 network per v2 rule.
  • low_rating store Rating 3.0 out of 5 with no disclosed review count; below-average trust signal.

Permissions Breakdown

  • tabs medium Can read tab URLs and titles; medium risk on its own but enables URL-based tracking.
  • content_scripts https://www.youtube.com/* medium Injects JS into all YouTube pages; scoped to one domain but runs on every visit.

Pillar Scores

Permissions1.80
Reputation7.50
Network2.00
Webstore4.50
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 06:27
Listing SHA 704e1f81ac1a…
Force block — not fired
Score recovered no
Elapsed 23.8s