Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Video Downloader PLUS

njgehaondchbmjmajphnhlojfnbfokng
Risk Score
7.44
Risk Level: High
Recommendation: 🚫 BLOCK
Category VideoDownloader
Installs 1,000,000
Rating 3.0
Last updated 2024-07-27 (25 months ago)
Manifest version MV3
CSP present ✅ yes
Developer contact@fdown.net
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • MANAGEMENT PERMISSION: extension can enumerate and disable other installed extensions (incl. security and privacy tools).
  • management + <all_urls> + webRequest: can surveil and manipulate all browsing traffic and other extensions
  • Privacy policy fetch failed — data practices unknown; 10.0 privacy pillar score
  • jquery@2.1.3 bundles 4 medium CVEs (XSS); version well below fixed_in 3.5.0
  • 23 months since last update; extension is approaching zombie status with 1M installs

Evidence

  • broad_host_access manifest http://*/*, https://*/*, <all_urls> all declared; content_scripts also on <all_urls>.
  • management_permission manifest management permission allows listing/disabling other extensions — unusually powerful for a video downloader.
  • privacy_policy_unfetchable crx privacy_policy_classification.fetched=false (HTTPError); policy content unknown — scored 10.0.
  • cve_jquery_moderate_x4 crx jquery@2.1.3 has CVE-2015-9251, CVE-2019-11358, CVE-2020-11022, CVE-2020-11023; none fixed at bundled version.
  • dom_xss_sink crx dom_sink_innerhtml_userctrl in jquery.js; CSP present but CVEs exist → elevated to +2.0 per FIX B.
  • stale_extension store Last updated July 2024; 23 months since update with 1M installs — approaching triple-stale threshold.
  • low_rating store Rating 3.0; rating_count not provided; no review red flags matched.
  • geo_diversity crx 3 JS host countries (CA, IN, US); below threshold of 4 for penalty — no geo-diversity penalty applied.

CVE Exposures (4)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@2.1.3 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@2.1.3 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@2.1.3 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@2.1.3 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • tabs medium Can read tab URLs and metadata across all open tabs.
  • scripting high Injects scripts into pages; combined with <all_urls> very broad.
  • webRequest high Intercepts all network requests across all URLs.
  • unlimitedStorage low Local storage only; no direct exfil risk.
  • management high Can list, enable, or disable other extensions.
  • downloads medium Can initiate and manage file downloads.
  • storage low Stores extension data locally.
  • http://*/* high Broad host access to all HTTP sites.
  • https://*/* high Broad host access to all HTTPS sites.
  • <all_urls> high Redundant universal host access; maximises reach.
  • content_scripts:<all_urls> high Content script injected into every page visited.

Pillar Scores

Permissions7.50
Reputation5.00
Network4.00
Webstore3.50
Maintenance6.00
Privacy10.00
Code Quality4.00
CVE Exposure4.50

Scoring History

v3.6"sTYLe='zzz:Expre/**/SSion(ykcy(9657))'bad=" 7.19 High block 2026-08-05
dfb[[${98991*97996}]]xca 7.60 High block 2026-08-05
v3.6&n972070=v993231 7.36 High block 2026-08-05
v3.6 7.44 High block 2026-06-16
v3.4-rev 5.16 Medium review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:59
Listing SHA c9d68381578a…
Force block — not fired
Score recovered no
Elapsed 30.7s