Are online video downloaders safe? 8 red flags we found in their code
Some are safe, many are not, and the video is rarely the risk. 8 red flags we found in the code of popular downloaders, and how to check any site yourself.
In short
Online video downloaders can be safe, but many are not, and the video file is rarely the danger. The risk is what surrounds the Download button: ads that open new tabs, requests to allow notifications, and apps you never needed. On 9 October 2026 we read the code of nine popular downloaders and found all three.
You want to save a video, you search for a downloader, and the page you land on is full of buttons. Is it safe to paste your link there? Most guides answer with a list of brand names, often their own. This page does something different. We read the code of nine popular downloader sites on 9 October 2026, wrote down what each one is set up to do, and turned it into eight red flags you can check on any site in two minutes.
The short answer: the video is rarely the danger
Most video downloaders are not viruses, and the MP4 you get is almost never the problem. The risk sits around the Download button: adverts, new tabs, permission requests and programs the page wants you to install.
Free downloader sites have to pay for servers, and most pay with ads. Some use well-behaved ads. Others use ad networks that open hidden windows, send notifications or push app downloads. The site itself may be honest about the video and still hand you to an advert that is not.
So the useful question is not "is this site safe?" in general. It is "what will this page do when I click?" That is something you can check, and the rest of this page shows how.
8 red flags, and where we found each one
Each red flag below is something a page does, not a feeling about it. Where we saw it in a real site's code, the table says which site and when. Sites change their code often, so treat every finding as true on the date shown, not forever.
| # | Red flag | What you see | What it can lead to | Where we saw it (our scan: 9 Oct 2026) |
|---|---|---|---|---|
| 1 | Ads that look like the Download button | Several big "Download" buttons | An ad page or a malware download | AhnLab's reports on fake download sites (2025) |
| 2 | Your click opens something else | A new tab, or a full-screen ad first | Ad pages you did not ask for | y2mate, ssstik |
| 3 | Pop-under settings in the code | A window appears behind your browser | Ads that stay after you leave | 9xbuddy; ad-network tags on savethevideo and loader.to |
| 4 | It asks you to allow notifications | "Click Allow to continue" | Ad messages after you close the site | Code on y2mate |
| 5 | It wants you to install something | "Get our app", an APK, an extension, a "player" | Programs with far more access than a web page | savefrom, loader.to |
| 6 | The file is not a video | .exe, .scr or .apk instead of .mp4 | A program that runs on your device | The pattern in AhnLab's reports |
| 7 | It asks for your login | A box for your Google, Instagram or TikTok password | Someone else in your account | Not on these nine sites; watch for it anyway |
| 8 | A "safe" badge it gave itself | "Totally safe", "Norton Safe Web", "secure space" | False trust | savefrom, savepin, loader.to |
1. Ads that look like the Download button
The oldest trick is an advert dressed as the button you want. You see three green "Download" buttons, and only one of them gives you the video.
This is not a guess. In July 2025, the security team AhnLab ASEC described a fake video download site where "Clicking the 'Download Now' button redirects the user either to an advertisement page or to a malware download page." The file it served was named FirmwareUpdate.exe or NetworkSpeedStatus.exe, and it installed proxyware, a program that lets other people use your internet connection without asking you.
Google forbids this in its own ad programme. Its AdSense policy says publishers may not place ads "in a way that might be mistaken for menu, navigation or download links". So when a page shows several download buttons, at least one of them breaks the rules of the biggest ad network there is.
2. Your click opens something else
On a safe page, pressing Download does one thing: it downloads your file. If a new tab opens, or a full-screen advert appears first, the click has been given to someone else.
On y2mate (which now redirects to y2mate.gs), the page's own script opens a new tab the first time you press its download button. The address of that tab is hidden in the code with base64, a simple way of writing text so it is not readable at a glance. Decoded, it is etacloud.org. Your file comes after the tab.
On ssstik, clicking certain links opens a full-screen ad window first. On an iPhone, if Google's own full-screen ad did not load, the script stops your click and only follows the link two seconds later.
Google's list of abusive experiences names this pattern exactly: "Page features such as scroll bars, play buttons, 'next' arrows, close buttons, or navigation links that lead to an ad or landing page when clicked."
3. Pop-under settings in the code
A pop-under is a window that opens behind your browser, so you find it later and do not know where it came from. It is the hardest red flag to notice, because you never see it happen.
On 9xbuddy, the page's settings name it outright: "popunderUrl":"https://eo.khanumeryngo.cfd/...", with a second "inPageUrl" ad on the same address. On savethevideo, the page carries a site-verification tag named propeller, which is how the PropellerAds network confirms a publisher. On loader.to, the error filter in the page ignores errors from a list of ad addresses, including push-sdk.com, propu.sh and monetag. That suggests those scripts run there, though the filter alone does not prove it.
AdSense does not allow ads "Displayed in pop-ups or pop-unders". A site with a pop-under setting is using an ad network outside those rules.
4. It asks you to allow notifications
A page that says "Click Allow to download" or "Press Allow to confirm you are not a robot" is asking for permission to send you messages, not to give you a video. Once allowed, the site can keep sending them after you close it, and the messages often look like system warnings.
On y2mate, pressing convert loads a script from 9hito.com, whose address is again hidden with base64. The site also serves a small file called sw.hid.js. Its only line loads more code from 9hito.com. A file like this is a service worker: the part of a website that keeps running after the tab is closed, and the way browser notifications are delivered. The 9hito file is 118 KB of scrambled code, and among its names are notificationsCount and pushTraceId.
You never need to allow notifications to download a video. Chrome agrees: "When you browse sites with intrusive or misleading notifications, Chrome automatically blocks notifications."
Notice that y2mate hid both third-party addresses with base64. A page has no reason to hide where its own download comes from. Hiding the address of an ad script keeps it from simple ad blockers and from people who read the code. That is not proof of harm, but it is a reason to trust the page less.
5. It wants you to install something
A web downloader needs nothing installed for public videos on most sites. When a page pushes an app, an APK (an Android app file), a browser extension or a "video player" first, ask why.
On savefrom, the page links to an Android app file, sf-3.2.20-3120.apk, on another domain, downloadhelper.app, and promotes its browser extension. On loader.to, the page links to loader.apk. An app or extension can reach far more of your device than a web page. Our Android guide explains why downloader APKs are a risk.
In August 2025, AhnLab found another fake download site where the Download button gave out a file named Setup.exe, disguised as a memory cleaner called WinMemoryCleaner. It quietly added two scheduled tasks to Windows and installed proxyware.
6. The file is not a video
A video ends in .mp4, .webm or .mov, and sound in .mp3 or .m4a. If what arrives ends in .exe, .msi, .scr, .bat, .apk or .dmg, it is a program, not your video. Do not open it.
Windows hides the ending of common file types by default, so video.mp4.exe can look like video.mp4. Microsoft's help page shows how to turn endings on in Windows 11: in File Explorer, select View, then Show, then File name extensions. Do it once, and the trick stops working on you.
A file that is far too small is another sign. A 20-minute video in HD is not a few hundred kilobytes.
7. It asks for your login
No downloader website needs your Google, Instagram, TikTok or Facebook password to save a public video. Your login is the key to your whole account. A site that asks for it can read your messages, change your password or post as you. We explain this in more detail in our guide on why you should never give a downloader website your Google login.
If a video can only be seen after signing in, it is private or limited on purpose. A safe downloader says no to it instead of asking for your password.
8. A "safe" badge it gave itself
A badge on a page is a picture. Anyone can put one there. On 9 October 2026, savefrom showed a "Norton Safe Web" badge, savepin said "SavePin is totally safe, secure, and compatible with all devices", and loader.to said "We offer you a secure space free of such threats" on the same page as the ad-address list above.
Watch the address too. y2mate.nu now sends you to y2mate.gs, and en.savefrom.net sends you to en1.savefrom.net/19wr/. Sites that keep moving are hard to judge, because a clean report about one address says nothing about the next.
Why a clean scan does not prove a site is safe
A "scanned clean" badge or a clean result in an online URL checker means the site's own address looked fine on the day it was checked. It says nothing about the ads, and the ads are the risky part.
Here is why. The ad code in a downloader page points at other addresses, and those change all the time. On 4 October 2026, 9xbuddy's pop-under setting pointed at ms.corantohughes.cyou. Five days later, on 9 October, it pointed at eo.khanumeryngo.cfd. A scan of 9xbuddy.site would look the same on both days. A scan of the ad address from 4 October tells you nothing about the one from 9 October.
The same goes for the padlock. HTTPS only means the connection between you and the site is private. Every one of the nine downloader sites we checked uses HTTPS, including the ones with pop-under and notification code. A padlock tells you who you are talking to, not whether they behave well.
So use scanners for what they are good at, checking a file you already have or a site you have never heard of, but do not let a green result replace the eight checks above.
Can a video file itself carry a virus?
Rarely. A real MP4 or MP3 is data, not a program. It cannot start by itself; a video player reads it. Almost all infections that start on a downloader site come from a program that the page offered, not from the video.
There are two exceptions worth knowing:
- A program that only looks like a video. This is red flag 6:
video.mp4.exewith the ending hidden. Turn file name extensions on and this trick fails. - A bug in your video player. Players have security holes from time to time. VLC's bulletin for version 3.0.24 (September 2026) says "Crafted files or streams can trigger these issues during opening, metadata preparsing, or playlist processing", in formats that include MP4, Matroska and AVI. It adds: "Code execution has been demonstrated on macOS under specific conditions." The fix was to upgrade to 3.0.24.
So the honest answer is: a video file is very unlikely to harm you, and an updated player makes it less likely still. Keep your player and your phone updated, and the video is the least of your worries.
Websites, extensions, apps and APKs: what each can reach
The more you install, the more a downloader can reach. That is the main difference between the kinds of downloader, and the main reason a website is usually the safest place to start.
| Kind of downloader | What it can reach | What to check before you use it |
|---|---|---|
| Website | Only the page you have open, plus anything you allow (notifications) | The eight red flags above |
| Browser extension | The sites it is allowed on, and anything its permissions grant | Where it works and what each permission is for |
| Desktop app (Windows, Mac) | Your files and your internet connection | Who made it, where you got it, and whether it is signed |
| Android APK from a website | Your phone, with no Play Store review | Whether you need it at all |
| "Cracked" or "premium unlocked" program | Anything | Do not install it |
Browser extensions: read the permissions
Chrome shows a warning for each permission that can reach your data. The permissions list for developers says what each one shows. For example, "tabs" shows "Read your browsing history", and "downloads" shows "Manage your downloads". Others, like "storage", "contextMenus" and "activeTab", show no warning, because they reach nothing on their own.
The question to ask is: does this extension need that much? A downloader needs to work on video sites. It does not need to read and change data on every website you visit. In Chrome, open the extension's Details and look at Site access to see where it runs.
Desktop apps: who made the file?
On Windows, a program signed by its publisher shows that publisher's name when you run it. An unsigned program makes Windows show "Windows protected your PC". On a Mac, an app that Apple has not notarised needs Open Anyway in System Settings. Neither warning means the file is harmful. Both mean your computer cannot confirm who made it, so you need another way to check, such as a fingerprint (SHA-256) published by the maker.
APKs on Android
An APK from a website skips the Play Store's checks. Downloader apps are a common way to spread adware, and you rarely need one: a browser can save most public videos on Android. Our Android guide shows how.
Where a free downloader's money comes from
Running a downloader costs money: servers, bandwidth and the work of keeping up with every site's changes. A free site pays for that somehow, and almost always with ads. The kind of ads decides how safe it feels.
Google's ad programme, AdSense, has strict rules. It does not allow ads in pop-ups or pop-unders, ads placed so they "might be mistaken for menu, navigation or download links", or pages with "False claims of streaming content, or downloads". It also says sites "may not change user preferences, redirect users to unwanted websites, initiate downloads, include malware or contain pop-ups or pop-unders that interfere with site navigation."
So when a downloader page has pop-under settings or notification code, its ads come from networks that work outside those rules. That is the business behind red flags 2, 3 and 4: the site is free to you, and the ads pay for it in ways Google itself refuses to allow.
Google also watches for this from the search side. Its Search Central guide on social engineering says a page that leads people to deceptive content, including "via pop-ups, pop-unders, or other types of redirection", can be flagged, and Chrome may then show a red "Deceptive site ahead" warning. If you ever see that warning on a downloader, close the tab.
Check any downloader yourself in two minutes
You do not need to be technical to check a site. This is the method we used, cut down to what anyone can do on a computer. It takes about two minutes and works on any downloader.
- Count the buttons. Before you paste anything, look at the page. One box and one button is a good sign. Several big "Download" buttons is red flag 1.
- Paste a link you do not care about. Use a public video that does not matter to you. Press the button once and watch: does a new tab open? Does a full-screen ad appear? Does the browser ask to show notifications? If yes, close the tab and leave.
- Look at the code. Press Ctrl+U (in Chrome on a Mac, Option+Cmd+U) to see the page's source. Press Ctrl+F and search for
popunder,propeller,monetag,push,serviceWorkerandatob(. Finding one does not prove harm, but it tells you what the page is set up to do. - Check your notifications. In Chrome, open Settings, then Privacy and security, then Site settings, then Notifications. The downloader should not be in the list of sites allowed to send notifications.
- Check the file before you open it. Turn on file name extensions. The file should end in .mp4, .mp3 or another media ending, and its size should make sense for the video.
- Never type a password. No downloader needs it for a public video.
On a phone, steps 1, 2, 5 and 6 still work. If a page on your phone keeps opening tabs or asking for permissions, stop using it.
If you already clicked something
Do not panic. What to do depends on what happened.
- A tab or advert opened. Close it. On an updated browser, a page that opens by itself usually cannot install anything unless you run a file or allow something.
- You allowed notifications. Remove the site in Chrome: Settings, Privacy and security, Site settings, Notifications, then remove it from the allowed list. This stops the messages that keep coming after you closed the site.
- You added an extension. Open your browser's extensions page and remove anything you do not recognise.
- You ran a file. Uninstall what it installed, then follow the FTC's steps: stop signing in to online accounts on that device, update your security software, run a security scan, then change your passwords and turn on two-factor authentication, ideally from another device.
The FTC also lists signs that a device may have malware. These include a computer that slows down, freezes or crashes; a browser home page that changes or sends you to sites you did not choose; new toolbars or add-ons; and lots of pop-up ads, including ads on sites where you would not expect them.
We put our own site through the same test
A page like this is easy to write and hard to live up to, so here is how Raptor Downloader does against its own eight checks. We read our own page's code on the same day, 9 October 2026.
| Red flag | Raptor Downloader today |
|---|---|
| 1. Ads that look like Download | No ads at all. Our ads.txt file says "No advertising networks yet." |
| 2. Your click opens something else | No. Our code opens no new tabs. |
| 3. Pop-under settings | None. Besides our own scripts, the page loads one from outside: Cloudflare's bot check, which shows no ads |
| 4. Asks for notifications | No. Our site never asks. |
| 5. Wants you to install something | Not for most sites: the website does the job. The app and extension are optional, mainly for YouTube and Reddit |
| 6. File is not a video | Files arrive as video (MP4), sound (MP3), words (TXT), subtitles (SRT), a picture, or a ZIP of several |
| 7. Asks for your login | Never |
| 8. Self-awarded badge | No badge. This page and our promises say what to check instead |
Where we fall short. Our Windows app is not code-signed yet, so Windows shows "Windows protected your PC" and you have to click More info, then Run anyway. Our Mac app is not notarised by Apple yet, so it needs Open Anyway the first time. These are the same warnings we told you to take seriously above. Instead of asking you to trust us, we publish the SHA-256 fingerprint of every app file, and our Windows install guide shows how to check yours with one command. A matching fingerprint proves the file is exactly the one we published. It does not prove who we are, which is what signing would add.
Our extension is installed by hand until it is in the browser stores. It asks for four permissions: storage, contextMenus and activeTab, which show no warning, and downloads, which Chrome describes as "Manage your downloads" and which saves a full-size picture when you choose "This picture". It runs only on the video sites it supports, listed one by one, not on every website. Its other connection is to our app on your own computer. Our extension guide lists each permission and why.
What we keep. Links you paste are not stored or logged. Files are deleted about an hour after they are ready. We set no tracking or advertising cookies, and there are no accounts. The full list is on our privacy page. To stop automated abuse, the site may show a Cloudflare bot check, described on the same page.
Ads in the future. If we add ads one day, they will be Google AdSense ads, which by Google's own rules cannot be pop-ups, pop-unders or fake download buttons.
Limits. Our server reads about 15 links a minute for each visitor, files can be up to 1 GB and 3 hours long, and download buttons work for 30 minutes. YouTube and Reddit refuse our server, so on the website we say so; they work through the Windows and Mac app, which uses your own connection.
Safe is not the same as allowed
A safe downloader protects your device. It does not change what you are allowed to do with the video. Saving a public video does not give you the right to reuse it: copyright and the platform's terms still apply.
A safe downloader also refuses some things on purpose. It will not get around logins, paywalls, copy protection (DRM) or privacy settings. A site that offers to do that is taking a risk with your account or the law, and that alone is a reason not to trust it. Our guide on what no downloader should do for you explains where that line is.
Questions people ask
Can you get a virus from downloading a video?
Rarely from the video itself, often from what the download page pushes at you. The usual way people get infected is by running a program the page offered: an .exe, an .apk, a "player" or an extension. A real MP4 cannot run by itself, but keep your video player updated, because players have had bugs that a specially made file could trigger.
Can video files have viruses?
A real video file is data, not a program, so it cannot start by itself. The two real risks are a program that only looks like a video (for example video.mp4.exe) and an old video player with a security bug. Turn on file name extensions so you see the real ending, and keep your player updated.
Are free video downloader sites viruses?
The sites themselves are usually not viruses, but many earn money from ads that behave badly. On 9 October 2026 we found pop-under ad settings, a new tab opened on the Download click, and app downloads offered next to the video on popular sites. The danger is clicking the wrong thing, not visiting the page.
Is there a video downloader without ads?
Yes. We found no ad code on the open-source cobalt.tools on 9 October 2026, and Raptor Downloader shows no ads today. If we add ads later, they will be Google ads, and Google's rules do not allow pop-ups, pop-unders or ads that look like download links.
Should I install a video downloader extension?
Only if you need it, and only after reading what it asks for. An extension that can read and change all your data on every website can see far more than videos. Check where it works and what each permission is for, and remove it when you stop using it.
Why do pop-ups continue after I close the downloader site?
You probably allowed the site to send notifications. A site that has that permission can keep sending messages after you close it. In Chrome, open Settings, then Privacy and security, then Site settings, then Notifications, and remove the site from the allowed list.
Is it safe to download video from twitter?
The platform is not the risk; the downloader you use is. An X or TikTok video saved as an MP4 is as safe as any other video. Use a downloader that shows one button and opens nothing else, and only save public posts.
What is the safest video downloader?
The safest choice is the platform's own Save or Download button, when it has one. After that, pick a downloader that passes the eight checks on this page, such as one button, no new tabs, no notification request, nothing to install, a real video file and no login.
Sources
- Google AdSense Help: AdSense Program policies (deceptive placement, pop-ups and pop-unders)
- Google Search Console Help: Abusive experiences (misleading site behaviour, auto redirect)
- Google Search Central: Social engineering (phishing and deceptive sites)
- Google Chrome Help: Use notifications to get alerts
- Chrome for Developers: Permissions list (the warning each permission shows)
- Microsoft Support: Common file name extensions in Windows
- VideoLAN: Security bulletin VLC 3.0.24 (crafted media files)
- FTC Consumer Advice: Malware, how to protect against, detect and remove it
- AhnLab ASEC: Proxyware malware distributed on a YouTube video download site (30 July 2025)
- AhnLab ASEC: Proxyware disguised as WinMemoryCleaner on video download sites (21 August 2025)
First published . Written and checked by the Raptor Downloader team. Download only videos you own or have permission to use. Terms · Copyright and takedowns