Video Download Helper
lmjnegcaeklhafolokijcfjliaokphfk
Risk Score
3.27
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- webRequest + <all_urls> provides broad network visibility across every site visited.
- No developer name listed; identity accountability gap.
- Uninstall URL hijack flag set; extension registers an uninstall redirect.
- Privacy policy scoped to extension but lacks retention disclosure and third-party silence noted.
- 12 distinct external JS hosts contacted including a.com (ambiguous domain).
Evidence
- broad_host_access manifest <all_urls> host permission paired with webRequest and scripting; justified for VideoDownloader category.
- uninstall_url_hijack crx install_url_hijack=false but uninstall_url_hijack=true; extension registers uninstall redirect to unknown target.
- no_developer_name store developer_name is empty string; only email support@downloadhelper.net identifies developer.
- external_hosts crx 12 external JS hosts including a.com, bilibili, vk, youtube APIs; >3 distinct registrable domains.
- featured_by_google store is_featured_by_google=true; follows recommended practices badge present.
- privacy_policy_retention api Policy fetched, scoped, no data collection stated, but retention not disclosed and third_party_silence=true.
- cve_clean crx cve_findings_raw empty; no known vulnerable JS libraries bundled.
- code_quality_clean crx code_findings_raw empty, obfuscation_score=0.0; 28 JS files scanned with no dangerous patterns detected.
Permissions Breakdown
- tabs medium Can read tab URLs and metadata; needed for video detection across sites.
- offscreen low Creates offscreen document for background processing; low abuse potential.
- downloads medium Can trigger file downloads; core to stated functionality.
- sidePanel low Shows side panel UI; cosmetic/UX risk only.
- webRequest high Can observe all network requests; sensitive but core to video URL interception.
- webNavigation medium Tracks navigation events; used to detect video page loads.
- scripting medium Can inject scripts into pages; paired with <all_urls> increases reach.
- declarativeNetRequest medium Can modify/block network requests declaratively.
- storage low Local settings storage; minimal risk.
- notifications low Desktop notifications for download status.
- contextMenus low Adds right-click menu items; cosmetic.
- unlimitedStorage low Extended storage quota; needed for large media caching.
- <all_urls> high Host access to all URLs; broad but justified for video detection across any site.
Pillar Scores
Permissions4.50
Reputation5.50
Network2.50
Webstore4.50
Maintenance0.00
Privacy2.00
Code Quality0.00
CVE Exposure0.00
Scoring History
| sssiedneb23ce5bdp727562726963xsx | 3.06 | Low | review | 2026-09-07 |
| %22fsssiedxa sssiedx | 3.24 | Low | review | 2026-08-08 |
| 'fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 3.23 | Low | review | 2026-08-08 |
| 3.15 | Low | review | 2026-08-08 | |
| fsssiedxa$"sssiedx | 3.13 | Low | review | 2026-08-08 |
| <fsssiedxi xx psssiedx | 3.03 | Low | review | 2026-08-03 |
| <fsssiedxi$'sssiedx | 3.00 | Low | review | 2026-08-03 |
| <fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 3.38 | Low | review | 2026-08-03 |
| <fsssiedxa | 3.02 | Low | review | 2026-08-03 |
| fsssiedx<sssiedx | 2.97 | Low | review | 2026-08-03 |
| fsssiedxa<sssiedx | 2.77 | Low | review | 2026-08-01 |
| fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 2.94 | Low | review | 2026-08-01 |
| fsssiedxa"sssiedx | 2.88 | Low | review | 2026-08-01 |
| fsssiedxa | 2.93 | Low | review | 2026-08-01 |
| fsssiedxa$'sssiedx | 2.77 | Low | review | 2026-08-01 |
| sssieddrubricxsx | 3.17 | Low | review | 2026-08-01 |
| v3.6 | 3.27 | Low | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:53
Listing SHA
0f92d8795b2f…
Force block
— not fired
Score recovered
no
Elapsed
22.1s