SnapMaster – Screenshot & Editor
bllhjhfajpclmnlogplcfjjnlkmnlfmp
Risk Score
5.47
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension, data collection and 3rd-party sharing admitted.
- No developer identity: no name, no email, no verified publisher badge.
- scripting + <all_urls> enables script injection into every site the user visits.
- Description promises recording (tabCapture/desktopCapture) but permissions don't support it — permission/promise mismatch.
- months_since_update unknown and no store metadata; lifecycle and maintenance cannot be assessed.
Evidence
- host_permissions_all_urls manifest <all_urls> combined with scripting permission allows reading/injecting into every page visited.
- privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
- no_developer_identity store developer_name and developer_email both empty; no verified_publisher badge; no business identity.
- description_promise_mismatch store Promises recording but lacks tabCapture/desktopCapture permissions.
- no_csp manifest content_security_policy is null; MV3 strict default applies but no explicit policy declared.
- maintenance_unknown store last_updated and months_since_update are null; maintenance score treated conservatively.
- no_code_findings crx code_findings_raw is empty; obfuscation_score 0.0; 4 JS files scanned — no malicious signals detected.
- no_cve_findings crx cve_findings_raw is empty; no known-vulnerable libraries bundled.
Permissions Breakdown
- activeTab low Scoped to current tab on user action; limited reach.
- storage low Local key-value storage; standard for saving editor state.
- scripting medium Allows programmatic script injection into pages; medium risk on its own.
- <all_urls> high Host permission grants access to content of every site visited.
Pillar Scores
Permissions5.50
Reputation7.50
Network2.00
Webstore4.00
Maintenance5.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 08:09
Listing SHA
38cc980bfce9…
Force block
— not fired
Score recovered
no
Elapsed
—