Video & Audio Downloader
pchlfebelfohhojoomlngjbkcjponfha
Risk Score
5.10
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic policy — not scoped to this extension; admits data collection and third-party sharing (→ Privacy +10.0).
- webRequest + *://*/*allo ws interception of all HTTP traffic across every site visited.
- Developer uses yahoo.com free webmail with no verified business identity, raising accountability gap.
- install_url_hijack and uninstall_url_hijack both true — extension opens third-party URLs on install/uninstall.
- No CSP declared; 7 external JS hosts referenced including raw.github.com and stuartk.com.
Evidence
- privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → Privacy 10.0.
- install_uninstall_hijack crx install_url_hijack=true, uninstall_url_hijack=true; targets not resolved but pattern is hijack behavior.
- free_webmail_developer store Developer email chyer.webstore@yahoo.com; no verified business; free webmail raises Reputation floor.
- broad_host_webrequest manifest webRequest + *://*/* allows inspection of all browser traffic on every visited site.
- no_csp crx content_security_policy is null; MV3 strict default applies but 7 external hosts referenced in JS.
- external_hosts crx js_external_hosts includes raw.github.com, stuartk.com, webbrowsertools.com — 3 countries (CA, IN, US).
- low_rating store Rating 3.6 at 90k installs suggests user dissatisfaction; no review red flags matched.
- operator_cluster_dev_email api sibling_count=0 on compound fingerprint; dev_email dim shows 1 (self), no true sibling cluster.
Permissions Breakdown
- storage low Local state storage; low standalone risk.
- downloads medium Can initiate downloads to user disk; expected for downloader.
- webRequest high Can observe/intercept all HTTP requests across all sites via *://*/*.
- notifications low Can display desktop notifications; low risk standalone.
- *://*/* high Broad host access paired with webRequest enables full traffic inspection.
Pillar Scores
Permissions6.00
Reputation7.50
Network4.00
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:03
Listing SHA
f4c89b4ec50e…
Force block
— not fired
Score recovered
no
Elapsed
21.7s