Is OK.ru Downloader (IDL Helper) safe?

High risk

OK.ru Downloader is high risk. Whenever this extension detects a video player, it sends the page URL and a persistent install ID to api.videodlservice.com on load, no action needed. Captured on youtube.com with no consent prompt; runs on all sites, not just OK.ru.

idlhelper4v0.7.67.0Chrome Web Store
75Risk
Who publishes it

idlhelper4 - no other listings under this identity

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
idlhelper4

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Analytics pings browsing URL and install ID on every video page visit

Whenever this extension detects a video player, it sends the page URL and a persistent install ID to api.videodlservice.com on load, no action needed.

Captured on youtube.com with no consent prompt; runs on all sites, not just OK.ru.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You open any page that has a video player, YouTube, a news site, any host.

The extension's content script runs on all URLs due to its <all_urls> manifest match.

The extension did this

The extension immediately POSTs the page URL and your persistent install ID to api.videodlservice.com/stat/.

Transmission happens when the download widget is inserted, no download, no user click required.

02EvidenceNETWORK CAPTURE
Captured request
POSThttps://api.videodlservice.com/stat/
Captured during dynamic analysis (2026-04-23): 3 POSTs observed on youtube.com page load, no consent prompt shown.
Headers
Content-Typeapplication/json; charset=utf-8
Body
{
  "branch": "master",
  "hash": "40b5f995",
  "hid": "0a9249ff-6caf-484f-b425-432f0e9c7bb6",
  "project": "idl-downloader-ok-chrome",
  "type": "idl-helper",
  "version": "0.7.67.0",
  "format": "",
  "media_source": "https://www.youtube.com/watch?v=dQw4w9WgXcQ",
  "service": "gv",
  "action": "insertWidget"
}
03EvidenceFIELD TABLE
Fields sent in every analytics POST
FieldValueWhy it matters
Page URL
https://www.youtube.com/watch?v=dQw4w9WgXcQThe full address of the page you were visiting when the extension loaded.
Installation ID
0a9249ff-6caf-484f-b425-432f0e9c7bb6A UUID generated once at install time and kept forever; ties every visit report back to your browser.
Browser + extension version
version=0.7.67.0, branch=master, hash=40b5f995Identifies your browser family and the exact extension version running.
Action / event type
insertWidgetWhich in-extension event triggered the upload (e.g. widget load, download complete, screenshot).
04EvidenceCODE COMPARE
The code that does this

getSendEvent, analytics sender with no consent check

What it actually does
// content_script.js:13734 — ./src/utils/analytics/get-send-event.js
const getSendEvent = store => (
  async (data) => {
    const {
      defaultItem,
      hid,          // persistent UUID from chrome.storage.sync
      serviceName,
      utm,
    } = store.getState();
    // No check for agreeWithProcessingStatisticalData here
    const defData = {
      branch: config.branch,
      hash: config.hash,
      hid,
      project: config.extType,
      type: config.analyticsType,
      version: config.version,
      ...utm,
      format: defaultItem ? defaultItem.quality : "",
      media_source: window.location.href,  // current page URL
      service: serviceName,
    };
    try {
      const headers = [["Content-Type", "application/json; charset=utf-8"]];
      const body = JSON.stringify({ ...defData, ...data });
      network_sendPost(config.analyticsUrl, headers, body, true);
      // config.analyticsUrl = "https://api.videodlservice.com/stat/"
    } catch (e) {}
  }
);
05EvidenceTHIRD PARTY LIST
Analytics destination
  • api.videodlservice.com

    Developer analytics backend. Receives page URLs, install IDs, browser metadata, and event types per widget insertion. Also hosts config endpoints (banned-videos-urls, country).

What it can do

Permissions this extension asks for, as declared in version 0.7.67.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    http://*/*

  • Read and change your data on every secure site you visit

    https://*/*

  • Store data in your browser

    storage

  • Store an unlimited amount of data in your browser

    unlimitedStorage

Updated 30 September 2026hjppjkabmcjcmfoanoclkkjlcelepaeo