Is Video Downloader safe?

Medium risk

Video Downloader rewrites response headers for MP4 files and requests from noname.technology.

Video Downloader installs browser network rules that add Access-Control-Allow-Origin: * to matching MP4 responses, which can make cross-origin video responses readable by other pages. It also changes responses for requests initiated by noname.technology by removing frame and content-security headers and adding permissive CORS headers, except on YouTube-related domains.

technologynonamev0.1.11Chrome Web Store
45Risk
Who publishes it

technologynoname - no other listings under this identity

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
technologynoname

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-200
SourceAI SANDBOX

Video Downloader removes frame protections for noname.technology requests.

The extension installs a dynamic network rule for requests from noname.technology that changes request headers and strips frame-protection headers like X-Frame-Options and CSP, exposing page URLs and content to that site.

01EvidenceCAUSE EFFECT
What actually happens
You did this

A user action activates the extension behavior.

The extension did this

The extension installs a dynamic network rule that strips X-Frame-Options and Content-Security-Policy for requests initiated by noname.technology.

02EvidenceNETWORK CAPTURE
Captured request
GETnoname.technology
03EvidenceFIELD TABLE
Fields affected by the network rule
FieldValueWhy it matters
Page URL
https://example.com/article (illustrative)The URL identifies which page is involved in the request flow.
Request and response headers
Content-Security-Policy: frame-ancestors 'self' (illustrative)Headers control browser security behavior, including whether another site can frame a page.
Page content context
Rendered page content (illustrative)Removing frame protections can change how page content is made available in a remote site's frame.
04EvidencePLAIN NOTE
Observation

The confirmed evidence shows a dynamic rule scoped to initiatorDomains for noname.technology, with YouTube-related domains excluded from the rule installation path.

What it can do

Permissions this extension asks for, as declared in version 0.1.11. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    <all_urls>

  • Run its own code inside the pages you visit

    scripting

  • Store data in your browser

    storage

  • Watch every request your browser makes

    webRequest

  • Block and redirect the requests your browser makes

    declarativeNetRequest

  • Show a panel beside the page

    sidePanel

Where it sends data

Destinations our analysis observed Video Downloader contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • noname.technology

    Video Downloader sends data to noname.technology. One other extension we have analysed sends data here.

Updated 30 September 2026loiebadnnjhhmnphkihojemigfiondhf