Is Easy Video Downloader safe?
Easy Video Downloader is high risk. The service worker reads response headers of every image, video, audio and XHR/fetch request, not just video, under a site-wide *://*/* permission. It fired 28 times on one page, capturing a Google Ads pixel's headers. No send observed.…
Who publishes itYubi - 6 other listings from the same operator, none carrying a finding
Yubi - 6 other listings from the same operator, none carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
6 other listings published from this account, 319k+ users between them, none of them carrying a finding.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Video Downloader Reads Response Headers On Every Website You Visit
The service worker reads response headers of every image, video, audio and XHR/fetch request, not just video, under a site-wide *://*/* permission.
It fired 28 times on one page, capturing a Google Ads pixel's headers.
No send observed.
You browse to any website, whether or not it has a video on it.
The page just needs to load at least one image, video, audio, or XHR/fetch resource, which almost every page does.
The extension reads the response headers of that resource - and every other resource the page loads, including ones from other companies' servers.
This happens automatically, without you opening the download dialog or interacting with the extension.
| Field | Value | Why it matters | |
|---|---|---|---|
Resource address | https://cdn.viously.com/video/6f2a19d0.mp4 | The exact address of every image, video, audio and XHR/fetch resource loaded on the page, including ones pulled in from other sites. | |
Content type | video/mp4 | What kind of file was returned. Used to decide whether it's a downloadable video, image or audio file. | |
Content length | 10485760 | The size of the response in bytes. | |
Content disposition | attachment; filename="clip.mp4" | Filename metadata the server attached to the response, if any. | |
Tab and timestamp | tabId 482, 2026-08-30T16:24:11Z | Which browser tab the resource loaded in and when. Older records are dropped once more than 500 accumulate. |
The all-origins header listener (shipped unminified)
const onHeadersReceived = d => {
const {type, responseHeaders, tabId} = d;
if (tabId < 0) {
return;
}
if (type === 'image') {
push('image', d);
}
else {
// prevent YouTube video link detection!
if (d.url.includes('googlevideo.')) {
return;
}
const contentType = responseHeaders
.filter(o => o.name === 'content-type' || o.name === 'Content-Type')
.map(o => o.value).shift() || '';
if (
contentType.startsWith('text/') ||
contentType.startsWith('application/json')
) {
return;
}
if (
contentType.startsWith('image/') ||
['.jpg', '.jpeg', '.png', '.gif', '.bmp', '.tiff', '.webp', '.svg'].some(a => d.url.includes(a))
) {
push('image', d);
}
if (
contentType.startsWith('audio/') ||
['application/vnd.apple.mpegurl', 'application/x-mpegURL'].includes(contentType) ||
['.pcm', '.wav', '.mp3', '.aac', '.ogg', '.wma', '.m3u8', '.mpd'].some(a => d.url.includes(a))
) {
push('audio', d);
if (type === 'media') {
return;
}
}
if (
contentType.startsWith('video/') ||
['.flv', '.avi', '.wmv', '.mov', '.mp4', '.webm', '.mkv'].some(a => d.url.includes(a))
) {
push('video', d);
if (type === 'media') {
return;
}
}
}
};
chrome.webRequest.onHeadersReceived.addListener(onHeadersReceived, {
urls: ['*://*/*'],
types
}, ['responseHeaders']);- www.w3schools.com
The site being actively browsed; first-party video and image responses were inspected here.
- www.google.co.uk
Third-party Google Ads tracking-pixel response inspected by the same listener while browsing w3schools.com.
- cdn.viously.com
Third-party video CDN response inspected on the same page load.
- e.viously.com
Third-party analytics/beacon endpoint inspected via the extension's xmlhttprequest monitoring.
Illustrative record kept per detected media resource; up to 500 per tab, oldest evicted first, cleared on navigation or via clear-list.
Page-world object (window.video / window.image / window.audio), written into the tab via chrome.scripting.executeScript{
"https://cdn.viously.com/video/6f2a19d0.mp4": {
"type": "video",
"timestamp": 1756572251000,
"responseHeaders": [
{
"name": "content-type",
"value": "video/mp4"
},
{
"name": "content-length",
"value": "10485760"
}
]
}
}What it can do
Permissions this extension asks for, as declared in version 0.2.1. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on every site you visit
*://*/*
Watch every request your browser makes
webRequest
Add items to the right-click menu
contextMenus
Store data in your browser
storage
Start, monitor and manage your downloads
downloads
Run its own code inside the pages you visit
scripting