Screenshot and screen video recording - Screeny
djekgpcemgcnfkjldcclcpcjhemofcib
Risk Score
7.63
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Critically outdated JS libs: lodash+underscore with critical CVEs (prototype pollution, arbitrary code exec) bundled in extension injected on all sites.
- Privacy policy URL timed out (fetch_error) — effectively no verifiable privacy policy; scored as unfetched (+10.0).
- Developer uses free Gmail with no developer name listed; verified_publisher present but v3.5 invariant 0c caps discount due to stale+CVEs.
- Extension has been 18 months without update while bundling multiple high/critical severity vulnerable libraries across jquery, lodash, moment, underscore.
- <all_urls> content script injection paired with vulnerable DOM-manipulation libraries (jquery, underscore) raises XSS escalation risk on every visited page.
Evidence
- critical_cve_lodash crx lodash CVE-2019-10744 critical prototype pollution; underscore 1.8.3 CVE-2021-23358 arbitrary code exec (critical).
- high_cve_count crx 4 high-severity CVEs across lodash (x2), moment (x2); 7+ medium CVEs across jquery, lodash, moment.
- privacy_policy_timeout api fetch_error:ConnectTimeout on https://getscreeny.com/?p=privacy_policy — policy unverifiable.
- stale_extension store 18 months since last update; invariant 0c triggers: CVEs present + stale >18mo caps verified-publisher discount to -1.0.
- broad_host_access manifest <all_urls> in permissions + content_scripts_matches; content scripts injected on every site.
- free_webmail_dev store Developer email eugenijs98saulite@gmail.com; no developer name; free Gmail account.
- verified_and_featured store verified_publisher=true and is_featured_by_google=true; discounts apply but capped by invariant 0c.
- js_external_hosts_docs_only crx js_external_hosts are documentation domains (mozilla.org, jquery.com etc.) — no active CDN risk.
CVE Exposures (15)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2012-6708 | jquery@unknown | moderate | 1.9.0 | Cross-Site Scripting in jquery |
| CVE-2011-4969 | jquery@unknown | moderate | 1.6.3 | jQuery vulnerable to Cross-Site Scripting (XSS) |
| CVE-2015-9251 | jquery@unknown | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
| CVE-2021-23337 | lodash@unknown | high | 4.17.21 | Command Injection in lodash |
| CVE-2026-4800 | lodash@unknown | high | 4.17.21 | Command Injection in lodash |
| CVE-2018-16487 | lodash@unknown | high | 4.17.11 | Prototype Pollution in lodash |
| CVE-2025-13465 | lodash@unknown | moderate | 4.18.0 | lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and |
| CVE-2026-2950 | lodash@unknown | moderate | 4.18.0 | lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and |
| CVE-2018-3721 | lodash@unknown | moderate | 4.17.5 | Prototype Pollution in lodash |
| CVE-2019-10744 | lodash@unknown | critical | 4.17.12 | Prototype Pollution in lodash |
| CVE-2017-18214 | moment@unknown | high | 2.19.3 | Regular Expression Denial of Service in moment |
| CVE-2016-4055 | moment@unknown | moderate | 2.11.2 | Regular Expression Denial of Service in moment |
| CVE-2022-24785 | moment@unknown | high | 2.29.2 | Path Traversal: 'dir/../../filename' in moment.locale |
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- tabs medium Access to tab URLs and metadata across all tabs.
- <all_urls> high Broad host access enabling content script injection on every site.
- activeTab low Scoped to current tab on user action; low residual risk.
- storage low Local extension data storage.
- unlimitedStorage low Larger quota; needed for video/screenshot files.
- alarms low Scheduled background tasks.
- desktopCapture medium Can capture full screen, windows, or tabs — core to stated function but sensitive.
- identity low OAuth token access; no scopes declared, lower risk.
Pillar Scores
Permissions4.50
Reputation3.50
Network0.00
Webstore1.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure10.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 07:49
Listing SHA
818116611fa6…
Force block
— not fired
Score recovered
no
Elapsed
—