Video Downloader Pro
penndbmahnpapepljikkjmakcobdahne
Risk Score
4.22
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Free-webmail developer (gmail) with no verified business identity inflates impersonation/takeover risk.
- Content script injected into <all_urls> combined with <all_urls> host_permission gives full page-level access on every site.
- Uninstall URL hijack detected — extension registers a 3rd-party redirect on removal.
- Privacy policy admits data collection and third-party sharing but no retention period disclosed.
- CSP sandbox allows unsafe-inline and unsafe-eval; Function constructor present in background and ffmpeg bundle.
Evidence
- free_webmail_developer store developer_email save.highvideo@gmail.com — no verified business domain; +1.5 reputation penalty.
- uninstall_url_hijack crx uninstall_url_hijack == true; classic monetization/tracking redirect on removal. +3.0 webstore.
- all_urls_host_permission manifest <all_urls> in host_permissions AND content_scripts; broad reach across every site visited.
- csp_unsafe_eval_inline crx Sandbox CSP includes unsafe-inline and unsafe-eval on script-src; weakened code isolation.
- function_constructor_in_background crx new Function() found in js/background.js — dynamic code execution path in service worker.
- privacy_third_party_sharing_no_retention api Policy fetched; scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
- low_rating store Rating 2.7 — below 3.0 threshold; user dissatisfaction signal though review red flags clear.
- is_featured_by_google store Extension carries Google Featured badge; partial trust discount applied to reputation pillar.
Permissions Breakdown
- tabs medium Can read tab URLs and metadata; moderate risk when paired with <all_urls>.
- storage low Local extension storage only; low standalone risk.
- downloads medium Can initiate and manage file downloads; core to VideoDownloader function.
- *://*.aliyuncs.com/* medium Explicit host permission to Alibaba Cloud CDN; could relay content/data.
- declarativeNetRequest medium Can modify/block network requests; core to video interception but broad.
- alarms low Scheduled tasks only; low standalone risk.
- <all_urls> (host_permission) high Grants content-script and request access on every site; broadest reach.
- content_scripts: <all_urls> high Injects JS into every page; combined with downloads and tabs is high risk.
Pillar Scores
Permissions4.50
Reputation7.00
Network3.50
Webstore5.50
Maintenance0.00
Privacy2.00
Code Quality2.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:03
Listing SHA
34731cb11888…
Force block
— not fired
Score recovered
no
Elapsed
27.7s