Is Video Downloader Pro safe?
Video Downloader Pro is low risk. The extension bundles a GA4 client firing usage events on interaction: menu clicks, popup opens, downloads, errors. Each payload includes your tab URL, extension version, a session ID, and client ID, sent to google-analytics.com/mp/collect.
Who publishes itfrank.shockley - no other listings under this identity
frank.shockley - no other listings under this identity
What this publisher told the store about itself, and the other listings that told it the same thing.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Extension sends visited tab URLs to Google Analytics on each interaction
The extension bundles a GA4 client firing usage events on interaction: menu clicks, popup opens, downloads, errors.
Each payload includes your tab URL, extension version, a session ID, and client ID, sent to google-analytics.com/mp/collect.
You use the extension on any page, opening the popup, triggering a download, using a context menu, or when an error occurs.
The content script sends a ga-msg message to the background service worker carrying the current tab URL.
The service worker POSTs a GA4 event to Google Analytics including the tab URL, extension version, a session ID, and a persistent client ID.
The client ID is generated once via crypto.randomUUID() and stored in chrome.storage.local, creating a long-lived per-install identifier.
GA4 Analytics class, fireEvent method
// background.js lines 14546–14654 (Analytics class)
const GA_ENDPOINT = 'https://www.google-analytics.com/mp/collect';
class Analytics {
constructor(measurementId, apiSecret) {
this.MEASUREMENT_ID = measurementId;
this.API_SECRET = apiSecret;
}
async getOrCreateClientId() {
let { clientId } = await chrome.storage.local.get('clientId');
if (!clientId) {
clientId = self.crypto.randomUUID(); // persistent per-install UUID
await chrome.storage.local.set({ clientId });
}
return clientId;
}
async fireEvent(eventName, params = {}) {
const sessionId = await this.getOrCreateSessionId();
params.session_id = params.session_id ?? sessionId;
params.engagement_time_msec = params.engagement_time_msec ?? 100;
const clientId = await this.getOrCreateClientId();
await fetch(
`${GA_ENDPOINT}?measurement_id=${this.MEASUREMENT_ID}&api_secret=${this.API_SECRET}`,
{ method: 'POST',
body: JSON.stringify({ client_id: clientId, events: [{ name: eventName, params }] }) }
);
}
}
// Caller (Ga wrapper, lines 14759-14768):
async sendGaEvent(eventName, tabUrl, extraParams = {}) {
return this.analytics.fireEvent(eventName, {
tabUrl, // <-- current tab URL in every event
...extraParams,
version: chrome.runtime.getManifest().version
});
}- www.google-analytics.com
Google Analytics 4 Measurement Protocol, receives usage events including tab URL, session ID, client UUID, and extension version on every user interaction.
What it can do
Permissions this extension asks for, as declared in version 3.8.4. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to. The current listed version is 3.8.5, which we have not unpacked yet.
Read and change your data on every site you visit
<all_urls>
See the address and title of every tab you have open
tabs
Watch every request your browser makes
webRequest
Run its own code inside the pages you visit
scripting
Store data in your browser
storage
Store an unlimited amount of data in your browser
unlimitedStorage
Start, monitor and manage your downloads
downloads
Block and redirect the requests your browser makes
declarativeNetRequest
Add items to the right-click menu
contextMenus
Show you desktop notifications
notifications
Capture the video and audio of a tab
tabCapture