Video Downloader PLUS
njgehaondchbmjmajphnhlojfnbfokng
Risk Score
7.44
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- MANAGEMENT PERMISSION: extension can enumerate and disable other installed extensions (incl. security and privacy tools).
- management + <all_urls> + webRequest: can surveil and manipulate all browsing traffic and other extensions
- Privacy policy fetch failed — data practices unknown; 10.0 privacy pillar score
- jquery@2.1.3 bundles 4 medium CVEs (XSS); version well below fixed_in 3.5.0
- 23 months since last update; extension is approaching zombie status with 1M installs
Evidence
- broad_host_access manifest http://*/*, https://*/*, <all_urls> all declared; content_scripts also on <all_urls>.
- management_permission manifest management permission allows listing/disabling other extensions — unusually powerful for a video downloader.
- privacy_policy_unfetchable crx privacy_policy_classification.fetched=false (HTTPError); policy content unknown — scored 10.0.
- cve_jquery_moderate_x4 crx jquery@2.1.3 has CVE-2015-9251, CVE-2019-11358, CVE-2020-11022, CVE-2020-11023; none fixed at bundled version.
- dom_xss_sink crx dom_sink_innerhtml_userctrl in jquery.js; CSP present but CVEs exist → elevated to +2.0 per FIX B.
- stale_extension store Last updated July 2024; 23 months since update with 1M installs — approaching triple-stale threshold.
- low_rating store Rating 3.0; rating_count not provided; no review red flags matched.
- geo_diversity crx 3 JS host countries (CA, IN, US); below threshold of 4 for penalty — no geo-diversity penalty applied.
CVE Exposures (4)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@2.1.3 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@2.1.3 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@2.1.3 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@2.1.3 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- tabs medium Can read tab URLs and metadata across all open tabs.
- scripting high Injects scripts into pages; combined with <all_urls> very broad.
- webRequest high Intercepts all network requests across all URLs.
- unlimitedStorage low Local storage only; no direct exfil risk.
- management high Can list, enable, or disable other extensions.
- downloads medium Can initiate and manage file downloads.
- storage low Stores extension data locally.
- http://*/* high Broad host access to all HTTP sites.
- https://*/* high Broad host access to all HTTPS sites.
- <all_urls> high Redundant universal host access; maximises reach.
- content_scripts:<all_urls> high Content script injected into every page visited.
Pillar Scores
Permissions7.50
Reputation5.00
Network4.00
Webstore3.50
Maintenance6.00
Privacy10.00
Code Quality4.00
CVE Exposure4.50
Scoring History
| v3.6"sTYLe='zzz:Expre/**/SSion(ykcy(9657))'bad=" | 7.19 | High | block | 2026-08-05 |
| dfb[[${98991*97996}]]xca | 7.60 | High | block | 2026-08-05 |
| v3.6&n972070=v993231 | 7.36 | High | block | 2026-08-05 |
| v3.6 | 7.44 | High | block | 2026-06-16 |
| v3.4-rev | 5.16 | Medium | review | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:59
Listing SHA
c9d68381578a…
Force block
— not fired
Score recovered
no
Elapsed
30.7s