CRX aminer
Extension icon

Video DownloadHelper

Version 10.2.40.2 View in Chrome Web Store

Last scanned: about 4 hours ago

Extension Details

Developer: SAS ACLAP
Rating: 4.4 ★ (31.7K ratings)
Users: 5,000,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

Video DownloadHelper has strong legitimacy indicators with 5 million users, a solid 4.4-star rating from over 31,000 reviews, and is developed by SAS ACLAP, a known company in this space. The extension's core functionality of downloading videos from various platforms aligns with its requested permissions, suggesting legitimate business purpose rather than malicious intent.

Concerns:

The extension's critical risk rating stems from its extensive permission set that creates significant attack surface. The combination of webRequest interception, broad host permissions across all URLs, and unsafe WebAssembly execution creates potential for data theft, request manipulation, and hidden malicious code execution. While the tabs, downloads, and webNavigation permissions are functionally necessary for video downloading, they also enable comprehensive browsing surveillance. The unlimited storage permission could facilitate large-scale data collection. The specific content script injections across major video platforms (YouTube, Vimeo, Facebook, etc.) are expected but expand the potential impact zone.

Recommendations:

Given the critical risk level, install this extension in a dedicated Chrome profile isolated from sensitive browsing activities. Avoid using it while logged into important accounts or accessing confidential information. Regularly review the extension's behavior and consider alternatives with more limited permissions if available. The high user base and ratings suggest the developer is likely trustworthy, but the extensive permissions create inherent risks that warrant careful containment.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: downloads
This extension has the downloads permission. Can download files and access download history. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
HIGH
Unsafe WebAssembly Execution
This extension's Content Security Policy allows 'wasm-unsafe-eval', which permits potentially dangerous WebAssembly code execution. This could be used to hide malicious code or perform CPU-intensive operations.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: notifications
This extension has the notifications permission. Can show notifications.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Medium-Risk Permission: unlimitedStorage
This extension has the unlimitedStorage permission. Can store unlimited data locally.