Screenshot Tool - Screen Capture & Editor
edlifbnjlicfpckhgjhflgkeeibhhcii
Risk Score
4.92
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- jquery@3.2.1 bundles 3 unpatched medium CVEs (XSS); library below fixed_in 3.5.0 with no CSP amplifies risk.
- scripting + <all_urls> host permission enables arbitrary JS injection on every visited page.
- Gmail-only developer identity (no dev name, free webmail) reduces accountability.
- Privacy policy discloses third-party sharing but omits retention; screenshot tool with broad host access is high-impact.
- 17 months since last update; CVEs and stale code compound under v3.5 invariant 0c cap.
Evidence
- host_permissions_all_urls + scripting manifest Extension declares <all_urls> host_permissions and scripting; content scripts also match <all_urls>.
- cve_jquery_3_medium_x3 crx jquery@3.2.1 has 3 medium CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); all fixed above 3.5.0.
- no_csp crx content_security_policy is null; MV3 default applies but CVE amplifier triggers (jquery DOM-manip lib + medium CVEs).
- function_constructor_usage crx new Function() found in js/editor.js and js/lib/fabric.js; dynamic code execution risk.
- developer_identity store developer_name empty; developer_email is free webmail (gisstapa@gmail.com); no business domain verifiable.
- verified_publisher + featured store verified_publisher=true and is_featured_by_google=true; discounts applied but capped per 0c (months_since_update=17).
- privacy_policy_third_party_sharing api Policy fetched; scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
- description_promise_mismatch store Description promises recording but extension lacks tabCapture/desktopCapture permissions.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@3.2.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.2.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.2.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- storage low Local key-value store; low impact on its own.
- unlimitedStorage low Extends storage quota; no cross-origin access.
- scripting high Programmatic script injection into pages; paired with <all_urls> host permission.
- <all_urls> (host_permissions) high Grants content script + scripting access to every URL the user visits.
- <all_urls> (content_scripts) high Content script injected on every page; broad data-read surface.
Pillar Scores
Permissions5.50
Reputation5.50
Network2.00
Webstore3.50
Maintenance6.00
Privacy2.00
Code Quality4.50
CVE Exposure5.00
Scoring History
| <fsssiedxa$'sssiedx | 4.25 | Medium | review | 2026-08-13 |
| <fsssiedxa'sssiedx | 4.22 | Medium | review | 2026-08-13 |
| <fsssiedxa$"sssiedx | 4.36 | Medium | review | 2026-08-13 |
| <fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 4.51 | Medium | review | 2026-08-13 |
| <fsssiedxa | 4.32 | Medium | review | 2026-08-13 |
| fsssiedxa<sssiedx | 4.20 | Medium | review | 2026-08-13 |
| %22fsssiedxi$'sssiedx | 4.43 | Medium | review | 2026-08-04 |
| 4.27 | Medium | review | 2026-08-04 | |
| <fsssiedxi"sssiedx | 3.79 | Low | review | 2026-08-04 |
| <fsssiedxf"sssiedx | 4.14 | Medium | review | 2026-08-04 |
| <fsssiedxa xx psssiedx | 4.43 | Medium | review | 2026-08-04 |
| <fsssiedxi sssiedx | 4.36 | Medium | review | 2026-08-04 |
| fsssiedx<sssiedx | 4.17 | Medium | review | 2026-08-04 |
| fsssiedxasssiedx | 4.43 | Medium | review | 2026-07-28 |
| fsssiedxa'sssiedx | 4.57 | Medium | review | 2026-07-28 |
| fsssiedxa | 4.15 | Medium | review | 2026-07-28 |
| sssieddrubricxsx | 4.16 | Medium | review | 2026-07-28 |
| v3.6 | 4.92 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:29
Listing SHA
22a38b9aa6df…
Force block
— not fired
Score recovered
no
Elapsed
29.7s