CRX aminer

Starting analysis...

Extension icon

Simple Douyin Downloader 简单抖音下载器

Version 1.6 View in Chrome Web Store

Last scanned: about 1 month ago | force re-scan

Extension Details

Rating: 3.6 ★ (28 ratings)
Users: 7,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension has a modest user base of 7,000 users with a below-average rating of 3.6 stars from only 28 reviews, which suggests limited user satisfaction or engagement. The lack of clear developer information raises transparency concerns. The extension targets Douyin (TikTok's Chinese version), indicating it serves a specific regional market for video downloading functionality.

Concerns:

The extension's permission set is concerning given its stated purpose. While webRequest and downloads permissions are technically necessary for video downloading functionality, they create significant security risks. The webRequest permission allows interception and modification of all web traffic, which far exceeds what's needed for simple video downloading. The broad host permissions extend beyond just Douyin domains to include content delivery networks, potentially allowing access to sensitive data across multiple sites. The Content Security Policy allowing localhost connections suggests development/debugging features that shouldn't be present in production releases.

Recommendations:

Consider running this extension in a separate Chrome profile to isolate potential security risks. Before installation, verify that video downloading complies with Douyin's terms of service and local copyright laws. Monitor the extension's network activity if possible, and consider alternative video downloaders with more restrictive permissions and better developer transparency. Given the high-risk permission combination, users should exercise extreme caution and consider whether the functionality is worth the security trade-offs.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: downloads
This extension has the downloads permission. Can download files and access download history. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.