Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

FetchV - Video Downloader for m3u8 & hls

nfmmmhanepmpifddlkkmihkalkoekpfd
Risk Score
4.72
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VideoDownloader
Installs 800,000
Rating 4.9
Last updated 2025-09-24 (12 months ago)
Manifest version MV3
CSP present ❌ no
Developer waddonx@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's own account policy — not scoped to this extension; admits data collection and 3rd-party sharing.
  • Free-webmail dev (waddonx@gmail.com) with no developer name; accountability is low.
  • broad host permissions (https://*/*, http://*/*) + scripting + webRequest gives full page visibility on every site.
  • No CSP (MV3 default applies but no explicit policy); 6 external JS hosts including CDNs loaded at runtime.
  • Description-permission mismatch: promises download capability but lacks 'downloads' permission.

Evidence

  • privacy_policy_generic store Policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • free_webmail_developer store developer_email=waddonx@gmail.com, developer_name empty; no verified business identity.
  • broad_host_access manifest host_permissions=[https://*/*, http://*/*] combined with scripting and webRequest covers all sites.
  • verified_publisher_featured store verified_publisher=true and is_featured_by_google=true; reduces reputation risk.
  • external_js_hosts crx 6 external hosts: aomediacodec.github.io, fetchv.net, getbootstrap.com, github.com, popper.js.org, www.webmproject.org.
  • description_permission_mismatch store promises download but lacks 'downloads' permission; likely uses alternative download method.
  • no_cve_no_obfuscation crx cve_findings_raw empty, obfuscation_score=0.0, code_findings_raw empty; clean code surface.
  • maintenance_ok store Last updated September 24 2025; 9 months since update → +1.5 maintenance penalty only.

Permissions Breakdown

  • tabs medium Can read tab URLs/titles; used for detecting video streams across all tabs.
  • webRequest high Intercepts all HTTP/S requests; core to HLS/m3u8 detection but high capability.
  • storage low Local state persistence; standard low-risk use.
  • declarativeNetRequest medium Can block/redirect network requests declaratively.
  • offscreen low Allows off-screen DOM; used for video processing without user-visible UI.
  • scripting high Can inject scripts into pages; combined with <all_urls> host access this is broad capability.
  • https://*/* high Broad host access covering all HTTPS sites; enables scripting/webRequest on every site.
  • http://*/* high Broad host access covering all HTTP sites; same surface as https://*/*.
  • <all_urls> (content_scripts) high Content scripts injected on every URL; large reach even for a video downloader.

Pillar Scores

Permissions5.50
Reputation5.50
Network3.50
Webstore3.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Scoring History

sssiedn8dcfa10fdp727562726963xsx 4.39 Medium review 2026-09-09
sssiedn688ee08cdp727562726963xsx 4.49 Medium review 2026-09-07
v3.6 4.72 Medium review 2026-06-16
v3.4-rev 4.61 Medium review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:58
Listing SHA 3dfd2c30c025…
Force block — not fired
Score recovered no
Elapsed 24.8s