Is Easy Video Downloader safe?

High risk

Easy Video Downloader is high risk. The service worker reads response headers of every image, video, audio and XHR/fetch request, not just video, under a site-wide *://*/* permission. It fired 28 times on one page, capturing a Google Ads pixel's headers. No send observed.…

75Risk
Who publishes it

Yubi - 6 other listings from the same operator, none carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-200
SourceAI SANDBOX

Video Downloader Reads Response Headers On Every Website You Visit

The service worker reads response headers of every image, video, audio and XHR/fetch request, not just video, under a site-wide *://*/* permission.

It fired 28 times on one page, capturing a Google Ads pixel's headers.

No send observed.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You browse to any website, whether or not it has a video on it.

The page just needs to load at least one image, video, audio, or XHR/fetch resource, which almost every page does.

The extension did this

The extension reads the response headers of that resource - and every other resource the page loads, including ones from other companies' servers.

This happens automatically, without you opening the download dialog or interacting with the extension.

02EvidenceFIELD TABLE
What gets read out of each response
FieldValueWhy it matters
Resource address
https://cdn.viously.com/video/6f2a19d0.mp4The exact address of every image, video, audio and XHR/fetch resource loaded on the page, including ones pulled in from other sites.
Content type
video/mp4What kind of file was returned. Used to decide whether it's a downloadable video, image or audio file.
Content length
10485760The size of the response in bytes.
Content disposition
attachment; filename="clip.mp4"Filename metadata the server attached to the response, if any.
Tab and timestamp
tabId 482, 2026-08-30T16:24:11ZWhich browser tab the resource loaded in and when. Older records are dropped once more than 500 accumulate.
03EvidenceCODE COMPARE
The code that does this

The all-origins header listener (shipped unminified)

What it actually does
const onHeadersReceived = d => {
  const {type, responseHeaders, tabId} = d;

  if (tabId < 0) {
    return;
  }
  if (type === 'image') {
    push('image', d);
  }
  else {
    // prevent YouTube video link detection!
    if (d.url.includes('googlevideo.')) {
      return;
    }

    const contentType = responseHeaders
      .filter(o => o.name === 'content-type' || o.name === 'Content-Type')
      .map(o => o.value).shift() || '';

    if (
      contentType.startsWith('text/') ||
      contentType.startsWith('application/json')
    ) {
      return;
    }

    if (
      contentType.startsWith('image/') ||
      ['.jpg', '.jpeg', '.png', '.gif', '.bmp', '.tiff', '.webp', '.svg'].some(a => d.url.includes(a))
    ) {
      push('image', d);
    }
    if (
      contentType.startsWith('audio/') ||
      ['application/vnd.apple.mpegurl', 'application/x-mpegURL'].includes(contentType) ||
      ['.pcm', '.wav', '.mp3', '.aac', '.ogg', '.wma', '.m3u8', '.mpd'].some(a => d.url.includes(a))
    ) {
      push('audio', d);
      if (type === 'media') {
        return;
      }
    }
    if (
      contentType.startsWith('video/') ||
      ['.flv', '.avi', '.wmv', '.mov', '.mp4', '.webm', '.mkv'].some(a => d.url.includes(a))
    ) {
      push('video', d);
      if (type === 'media') {
        return;
      }
    }
  }
};

chrome.webRequest.onHeadersReceived.addListener(onHeadersReceived, {
  urls: ['*://*/*'],
  types
}, ['responseHeaders']);
04EvidenceTHIRD PARTY LIST
Origins whose responses were inspected in one test page load
  • www.w3schools.com

    The site being actively browsed; first-party video and image responses were inspected here.

  • www.google.co.uk

    Third-party Google Ads tracking-pixel response inspected by the same listener while browsing w3schools.com.

  • cdn.viously.com

    Third-party video CDN response inspected on the same page load.

  • e.viously.com

    Third-party analytics/beacon endpoint inspected via the extension's xmlhttprequest monitoring.

05EvidenceSTORAGE DUMP
What's stored on your device

Illustrative record kept per detected media resource; up to 500 per tab, oldest evicted first, cleared on navigation or via clear-list.

LocationPage-world object (window.video / window.image / window.audio), written into the tab via chrome.scripting.executeScript
Contents (JSON)
{
  "https://cdn.viously.com/video/6f2a19d0.mp4": {
    "type": "video",
    "timestamp": 1756572251000,
    "responseHeaders": [
      {
        "name": "content-type",
        "value": "video/mp4"
      },
      {
        "name": "content-length",
        "value": "10485760"
      }
    ]
  }
}

What it can do

Permissions this extension asks for, as declared in version 0.2.1. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    *://*/*

  • Watch every request your browser makes

    webRequest

  • Add items to the right-click menu

    contextMenus

  • Store data in your browser

    storage

  • Start, monitor and manage your downloads

    downloads

  • Run its own code inside the pages you visit

    scripting

Updated 30 September 2026eaicplkoeceoelookkiaeekhodehdhde