FullPage Capture - Full Page Screenshot
ggacghlcchiiejclfdajbpkbjfgjhfol
Risk Score
3.55
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Free-webmail dev (gmail) with no developer name; verified badge exists but identity weak.
- Uninstall and install URL hijacks flagged — extension intercepts lifecycle events.
- description_promise mismatch: claims recording capability but lacks tabCapture/desktopCapture.
- <all_urls> host permission + scripting enables JS injection on every site user visits.
- Privacy policy admits third-party data sharing; no retention period disclosed.
Evidence
- install_url_hijack + uninstall_url_hijack crx Both install and uninstall URL hooks present; targets not resolvable — lifecycle tracking risk.
- developer_email free-webmail, no developer_name store maggiore55ferrari@gmail.com with empty developer_name; verified_publisher=true partially offsets.
- description_promise mismatch store Extension promises recording but declares neither tabCapture nor desktopCapture permissions.
- privacy_policy third_party_sharing=true, retention=false api Policy scoped to extension and admits data collection + 3rd-party sharing; no retention stated.
- js_external_hosts includes ntp.msn.com crx MSN NTP endpoint contacted alongside chrome/edge stores; unusual for screenshot tool.
- csp_present=false on MV3 manifest No explicit CSP declared; MV3 default applies but no explicit scoping present.
- verified_publisher + is_featured_by_google store Both badges present, partially mitigating reputation risk despite gmail identity.
- code_findings_raw empty, obfuscation_score=0.0 crx 18 JS files scanned; no malicious patterns or obfuscation detected.
Permissions Breakdown
- activeTab medium Grants access to current tab on user action; scoped but still captures tab content.
- scripting high Allows programmatic JS injection into pages; paired with <all_urls> host permission.
- storage low Local key-value storage only; standard for extension state.
- unlimitedStorage low Removes storage quota cap; reasonable for screenshot extension storing captures.
- webNavigation medium Observes navigation events across tabs; wider than strictly needed for screenshots.
- contextMenus low Adds right-click menu items; low-risk UI integration.
- <all_urls> high Host permission covering all sites; required for full-page capture but maximises reach.
Pillar Scores
Permissions5.50
Reputation5.50
Network3.00
Webstore5.50
Maintenance0.00
Privacy1.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 07:51
Listing SHA
075bee78a4a1…
Force block
— not fired
Score recovered
no
Elapsed
—