Fast save and repost for Instagram
olenolhfominlkfmlkolcahemogebpcj
Risk Score
6.02
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- cookies + <all_urls> + webRequest: can exfiltrate Instagram session tokens and observe all cross-site traffic
- Privacy policy is Google's generic account policy — does NOT scope to this extension; admits data collection and 3rd-party sharing
- Brand impersonation: extension targets Instagram but developer is unverified gmail user with no business domain
- Install-URL hijack opens www.instagram.com on install; content_scripts also inject into spector.ac/cx/team (unrelated to stated function)
- 5 distinct JS external hosts including downloadigs.com, spector.ac/cx/team — scope mismatch beyond Instagram-only stated purpose
Evidence
- cookies+<all_urls>+webRequest manifest cookies and webRequest both declared with <all_urls> host permission — multiplier applies; cross-site session exfil possible.
- brand_impersonation store brand_mention.is_impersonation=true for 'instagram'; developer is gmail user with no verified owner relationship.
- generic_privacy_policy store Policy URL is myaccount.google.com — scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
- install_url_hijack crx install_url_hijack=true targeting www.instagram.com; onInstalled opens 3rd-party URL.
- content_scripts_scope_mismatch manifest content_scripts run on spector.ac, spector.cx, spector.team — unrelated to Instagram downloader function.
- external_hosts crx 6 external JS hosts: downloadigs.com, spector.ac, spector.cx, spector.team, stuk.github.io, www.instagram.com.
- free_webmail_developer store developer_email=elmianoor7@gmail.com; no business domain; free webmail reputation floor applies.
- install_url_hijack_webstore store onInstalled opens 3rd-party URL (instagram.com) — +2.0 webstore signal applied.
Permissions Breakdown
- storage low Local state persistence; low risk.
- cookies high Can read/write all cookies on all URLs given <all_urls>; session hijack risk.
- downloads medium Can save files to disk; core to downloader function but abusable.
- tabs medium Can enumerate open tabs and URLs; privacy risk.
- webRequest high Can observe all network requests across all URLs; surveillance capability.
- system.display low Display info; unusual for a downloader but low direct harm.
- declarativeNetRequest medium Can block/modify network requests declaratively.
- <all_urls> high Broad host access amplifies cookies and webRequest to full cross-site capability.
Pillar Scores
Permissions7.50
Reputation7.50
Network3.50
Webstore7.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:02
Listing SHA
e5bc1d5b432d…
Force block
— not fired
Score recovered
no
Elapsed
24.6s