Is Video Downloader Global - videos & streams safe?
Video Downloader Global is high risk. When you submit feedback from the popup, the extension reads the current tab URL and sends it with your feedback text, issue type, email, and version to issues.statsforusers.com. No automatic request occurred without clicking feedback.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Feedback form sends tab URL and email to statsforusers.com
When you submit feedback from the popup, the extension reads the current tab URL and sends it with your feedback text, issue type, email, and version to issues.statsforusers.com.
No automatic request occurred without clicking feedback.
You submit the popup feedback form.
The relevant buttons set issue types such as not_detected and not_downloaded before the form is sent.
The extension sends your active tab URL, feedback text, email address, issue type, and extension version to a remote feedback endpoint.
The service worker encodes four user/form fields with base64 and posts the JSON package to issues.statsforusers.com.
| Field | Value | Why it matters | |
|---|---|---|---|
Current tab URL | https://app.example.com/projects/q3-budget/video-export (illustrative) | Shows the page you had open when submitting feedback. Full URLs can include private document names, search terms, or account paths. | |
Feedback message | The downloader does not detect this video (illustrative) | Contains the text you typed into the feedback box. | |
Email address | alex.rivera@example.com (illustrative) | Links the submitted feedback and page URL to you if you enter an email address. | |
Selected issue type | not_detected | Records which feedback button you selected before the form opened. | |
Extension version | 1.2.8 | Identifies which extension build sent the feedback. |
Popup collects form fields; service worker encodes and posts them
Mi(t) {
document.querySelector('.tech-form input[type="submit"]').addEventListener("click", (i => {
i.preventDefault();
let n = {
url: document.querySelector('[name="url"]').value,
comment: document.querySelector('[name="comment"]').value,
email: document.querySelector('[name="email"]').value,
issue_type: document.querySelector('[name="initButton"]').value
};
t(n)
}))
}
Si() {
this.Ai().then((t => {
j.Qt(t), this.ji({
onSubmit: t => {
chrome.runtime.sendMessage({
action: "techFeedback",
data: t
}, (function(t) {
j.Oi()
}))
}
})
}))
}
Ai: () => new Promise((t => {
chrome.tabs.query({
active: !0,
currentWindow: !0
}, (function(i) {
const n = i[0];
t(n.url)
}))
}))case "techFeedback":
return t.Hn(n.data), s({
success: !0
}), !0;
Hn(e) {
const t = {
u: btoa(encodeURIComponent(e.url)),
c: btoa(encodeURIComponent(e.comment)),
e: btoa(encodeURIComponent(e.email)),
i: btoa(encodeURIComponent(e.issue_type)),
v: chrome.runtime.getManifest().version
};
fetch(P().k, {
method: "POST",
body: JSON.stringify(t)
})
}- issues.statsforusers.com
Receives the feedback JSON package containing the encoded current tab URL, message, email address, selected issue type, and extension version.
What it can do
Permissions this extension asks for, as declared in version 1.2.8. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to. The current listed version is 1.2.6, which we have not unpacked yet.
Read and change your data on every site you visit
<all_urls>
Store data in your browser
storage
See the address and title of every tab you have open
tabs
Watch every request your browser makes
webRequest
Start, monitor and manage your downloads
downloads
Run hidden pages in the background
offscreen