Screen Recorder
bgnpgpfjdpmgfdegmmjdbppccdhjhdpe
Risk Score
5.34
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic policy — does not scope to this extension; data collection and 3rd-party sharing admitted without extension-specific disclosure.
- Promises screen recording but lacks tabCapture/desktopCapture permissions — likely a shell or bait-and-switch extension.
- Broad host permissions (<all_urls>) with content scripts on every site despite tiny install base (978) and no stated need.
- Extension is 18 months stale (borderline 12-24mo band) with no changelog visible.
- External JS loaded from vuejs.org (external CDN) with no CSP defined, raising supply-chain risk.
Evidence
- description_promise_mismatch crx promises recording but lacks tabCapture/desktopCapture — shell pattern suspected.
- generic_privacy_policy store Privacy URL is Google's own policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- broad_host_permissions manifest http://*/* + https://*/* + content_scripts <all_urls> with only 978 installs.
- install_perm_anomaly api small_install_high_perm=true, tail_attack_surface=true; 978 installs with HIGH-tier permissions.
- external_js_host crx vuejs.org listed as external JS host with no CSP — supply-chain risk.
- no_csp manifest content_security_policy is null; MV3 default helps but external JS host remains risky.
- stale_extension store 18 months since last update; borderline 12-24mo band.
- unverified_publisher store verified_publisher=false, is_featured_by_google=false; developer is 'AI Webcam Effects'.
Permissions Breakdown
- declarativeNetRequest medium Can intercept/block network requests; medium risk on its own without broad host pairing.
- http://*/* high Broad host access over all HTTP origins; content scripts injected everywhere.
- https://*/* high Broad host access over all HTTPS origins; paired with declarativeNetRequest raises risk.
- <all_urls> (content_scripts) high Content scripts injected on every site the user visits, expanding attack surface.
Pillar Scores
Permissions6.50
Reputation5.00
Network2.00
Webstore5.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 09:32
Listing SHA
bdf1ed6f8d87…
Force block
— not fired
Score recovered
no
Elapsed
—