Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Image Downloader Pro

nifhjlfnohgefbgeinfbbhpbndgomfnk
Risk Score
5.61
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category MediaDownloader
Installs 2,000
Rating 4.6
Last updated 2025-03-17 (15 months ago)
Manifest version MV3
CSP present ❌ no
Developer softroyals@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy — not scoped to this extension; admits data collection and third-party sharing.
  • Free-webmail developer (softroyals@gmail.com), no developer name, no business identity.
  • Broad host permissions (http://*/*, https://*/*) + scripting allow content access on all sites.
  • Install URL hijack opens internal options page on install — minor but flagged.
  • Extension is 15 months stale with no CSP; React 17 innerHTML sink present in bundled lib.

Evidence

  • privacy_policy_generic_google store Policy URL is myaccount.google.com/privacypolicy — Google's own policy, not scoped to this extension; scope_extension=false, data_collection=true, third_party_sharing=true.
  • free_webmail_developer_no_name store Developer email softroyals@gmail.com, developer_name empty, no business website. Floor reputation pillar at 7.5.
  • broad_host_permissions manifest host_permissions include http://*/*and https://*/* — effective <all_urls> access paired with scripting.
  • no_csp crx csp_present=false; MV3 has strict-ext default but no explicit CSP declared.
  • dom_sink_innerhtml_userctrl crx react-dom 17.0.2 bundles innerHTML assignment; no CSP and CVE-capable lib version.
  • install_url_hijack crx install_url_hijack=true; onInstalled opens /src/Options/index.html (internal page, lower severity).
  • stale_extension store Last updated March 2025; months_since_update=15, in 6–12mo band (+3.5 maintenance).
  • tail_attack_surface api install_perm_anomaly.tail_attack_surface=true: 2,000 installs with broad host+scripting permissions.

Permissions Breakdown

  • activeTab low Scoped to user-initiated action on current tab only.
  • scripting medium Enables JS injection into pages; paired with broad host permissions elevates risk.
  • downloads medium Can save files to disk; expected for a downloader tool.
  • http://*/* high Broad host access over all HTTP origins enables content reading on any site.
  • https://*/* high Broad host access over all HTTPS origins; same surface as <all_urls> in practice.

Pillar Scores

Permissions5.00
Reputation7.50
Network2.00
Webstore3.50
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:58
Listing SHA 8904da2d375c…
Force block — not fired
Score recovered no
Elapsed 25.0s