Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

IG Saver 2026 — Instagram Downloader for Photos, Videos, Reels & Stories

mmnhfflobddadjfnimkdhnpafpoggboo
Risk Score
3.34
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category MediaDownloader
Installs 7,000
Rating 4.8
Last updated 2026-05-15
Manifest version MV3
CSP present ❌ no
Developer chihyuwang83@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Instagram brand impersonation by free-webmail Gmail developer with no verified business identity.
  • new Function() constructor in offscreen.js enables dynamic code execution — code quality concern.
  • Unscoped host permission to api.polar.sh (payment/monetization API) not disclosed in description.
  • Privacy policy on free Google Sites host; no data retention clause; third-party sharing declared.
  • No CSP + DOM-XSS innerHTML sink elevates XSS risk if external content is injected.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true, confirmed_owner=false; Instagram brand used, dev is gmail.com.
  • free_webmail_developer manifest developer_email=chihyuwang83@gmail.com; no business domain or verified publisher badge.
  • featured_by_google store is_featured_by_google=true; partial trust signal offsetting reputation risk.
  • verified_publisher store verified_publisher=true; partial reputation discount applied.
  • function_constructor_finding crx new Function() in dist/offscreen.js; dynamic code execution path present.
  • unexpected_host_permission manifest api.polar.sh host permission present; this is a payment/monetization API not described.
  • privacy_policy_free_hosting store Policy on sites.google.com; scope_extension=true but retention=false, third_party_sharing=true.
  • no_csp manifest content_security_policy=null; MV3 so no +2 network penalty, but DOM-XSS risk elevated.

Permissions Breakdown

  • alarms low Scheduling only; minimal abuse surface.
  • downloads medium Can save files to disk; core to stated downloader function.
  • storage low Local state persistence; low impact alone.
  • offscreen low Offscreen document for media processing; needed for download logic.
  • host:https://www.instagram.com/* medium Content-script on Instagram; matches stated downloader purpose.
  • host:https://*.cdninstagram.com/* medium CDN fetch for media assets; matches downloader purpose.
  • host:https://*.fbcdn.net/* medium Facebook CDN for Instagram media; matches downloader purpose.
  • host:https://api.polar.sh/* medium External payment/monetization API unrelated to download function; unexpected scope.

Pillar Scores

Permissions2.50
Reputation6.50
Network1.50
Webstore3.50
Maintenance0.00
Privacy2.00
Code Quality5.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-15 14:29
Listing SHA e1362280ca74…
Force block — not fired
Score recovered no
Elapsed 26.6s