Is OK.ru Downloader (IDL Helper) safe?
OK.ru Downloader is high risk. Whenever this extension detects a video player, it sends the page URL and a persistent install ID to api.videodlservice.com on load, no action needed. Captured on youtube.com with no consent prompt; runs on all sites, not just OK.ru.
Who publishes itidlhelper4 - no other listings under this identity
idlhelper4 - no other listings under this identity
What this publisher told the store about itself, and the other listings that told it the same thing.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Analytics pings browsing URL and install ID on every video page visit
Whenever this extension detects a video player, it sends the page URL and a persistent install ID to api.videodlservice.com on load, no action needed.
Captured on youtube.com with no consent prompt; runs on all sites, not just OK.ru.
You open any page that has a video player, YouTube, a news site, any host.
The extension's content script runs on all URLs due to its <all_urls> manifest match.
The extension immediately POSTs the page URL and your persistent install ID to api.videodlservice.com/stat/.
Transmission happens when the download widget is inserted, no download, no user click required.
| Content-Type | application/json; charset=utf-8 |
{
"branch": "master",
"hash": "40b5f995",
"hid": "0a9249ff-6caf-484f-b425-432f0e9c7bb6",
"project": "idl-downloader-ok-chrome",
"type": "idl-helper",
"version": "0.7.67.0",
"format": "",
"media_source": "https://www.youtube.com/watch?v=dQw4w9WgXcQ",
"service": "gv",
"action": "insertWidget"
}| Field | Value | Why it matters | |
|---|---|---|---|
Page URL | https://www.youtube.com/watch?v=dQw4w9WgXcQ | The full address of the page you were visiting when the extension loaded. | |
Installation ID | 0a9249ff-6caf-484f-b425-432f0e9c7bb6 | A UUID generated once at install time and kept forever; ties every visit report back to your browser. | |
Browser + extension version | version=0.7.67.0, branch=master, hash=40b5f995 | Identifies your browser family and the exact extension version running. | |
Action / event type | insertWidget | Which in-extension event triggered the upload (e.g. widget load, download complete, screenshot). |
getSendEvent, analytics sender with no consent check
// content_script.js:13734 — ./src/utils/analytics/get-send-event.js
const getSendEvent = store => (
async (data) => {
const {
defaultItem,
hid, // persistent UUID from chrome.storage.sync
serviceName,
utm,
} = store.getState();
// No check for agreeWithProcessingStatisticalData here
const defData = {
branch: config.branch,
hash: config.hash,
hid,
project: config.extType,
type: config.analyticsType,
version: config.version,
...utm,
format: defaultItem ? defaultItem.quality : "",
media_source: window.location.href, // current page URL
service: serviceName,
};
try {
const headers = [["Content-Type", "application/json; charset=utf-8"]];
const body = JSON.stringify({ ...defData, ...data });
network_sendPost(config.analyticsUrl, headers, body, true);
// config.analyticsUrl = "https://api.videodlservice.com/stat/"
} catch (e) {}
}
);- api.videodlservice.com
Developer analytics backend. Receives page URLs, install IDs, browser metadata, and event types per widget insertion. Also hosts config endpoints (banned-videos-urls, country).
What it can do
Permissions this extension asks for, as declared in version 0.7.67.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on every site you visit
http://*/*
Read and change your data on every secure site you visit
https://*/*
Store data in your browser
storage
Store an unlimited amount of data in your browser
unlimitedStorage