FetchV - Video Downloader for m3u8 & hls
nfmmmhanepmpifddlkkmihkalkoekpfd
Risk Score
4.72
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's own account policy — not scoped to this extension; admits data collection and 3rd-party sharing.
- Free-webmail dev (waddonx@gmail.com) with no developer name; accountability is low.
- broad host permissions (https://*/*, http://*/*) + scripting + webRequest gives full page visibility on every site.
- No CSP (MV3 default applies but no explicit policy); 6 external JS hosts including CDNs loaded at runtime.
- Description-permission mismatch: promises download capability but lacks 'downloads' permission.
Evidence
- privacy_policy_generic store Policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
- free_webmail_developer store developer_email=waddonx@gmail.com, developer_name empty; no verified business identity.
- broad_host_access manifest host_permissions=[https://*/*, http://*/*] combined with scripting and webRequest covers all sites.
- verified_publisher_featured store verified_publisher=true and is_featured_by_google=true; reduces reputation risk.
- external_js_hosts crx 6 external hosts: aomediacodec.github.io, fetchv.net, getbootstrap.com, github.com, popper.js.org, www.webmproject.org.
- description_permission_mismatch store promises download but lacks 'downloads' permission; likely uses alternative download method.
- no_cve_no_obfuscation crx cve_findings_raw empty, obfuscation_score=0.0, code_findings_raw empty; clean code surface.
- maintenance_ok store Last updated September 24 2025; 9 months since update → +1.5 maintenance penalty only.
Permissions Breakdown
- tabs medium Can read tab URLs/titles; used for detecting video streams across all tabs.
- webRequest high Intercepts all HTTP/S requests; core to HLS/m3u8 detection but high capability.
- storage low Local state persistence; standard low-risk use.
- declarativeNetRequest medium Can block/redirect network requests declaratively.
- offscreen low Allows off-screen DOM; used for video processing without user-visible UI.
- scripting high Can inject scripts into pages; combined with <all_urls> host access this is broad capability.
- https://*/* high Broad host access covering all HTTPS sites; enables scripting/webRequest on every site.
- http://*/* high Broad host access covering all HTTP sites; same surface as https://*/*.
- <all_urls> (content_scripts) high Content scripts injected on every URL; large reach even for a video downloader.
Pillar Scores
Permissions5.50
Reputation5.50
Network3.50
Webstore3.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Scoring History
| sssiedn8dcfa10fdp727562726963xsx | 4.39 | Medium | review | 2026-09-09 |
| sssiedn688ee08cdp727562726963xsx | 4.49 | Medium | review | 2026-09-07 |
| v3.6 | 4.72 | Medium | review | 2026-06-16 |
| v3.4-rev | 4.61 | Medium | review | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:58
Listing SHA
3dfd2c30c025…
Force block
— not fired
Score recovered
no
Elapsed
24.8s