Screenshot Capture
giabbpobpebjfegnpcclkocepcgockkc
Risk Score
5.04
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and 3rd-party sharing.
- Extension has not been updated in ~31 months; bundled jquery@3.1.1 has 3 unpatched medium CVEs (XSS).
- No CSP present combined with vulnerable jQuery (DOM-manipulation lib) triggers CVE amplifier (×1.5 on CVE pillar).
- Description promises 'recording' capability but lacks tabCapture/desktopCapture — description/permission mismatch.
- 31-month staleness with multiple CVEs and Google generic privacy policy indicates governance neglect.
Evidence
- jquery@3.1.1 bundled — 3 medium CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023), fixed in 3.5.0 crx vendor/jquery.min.js version 3.1.1 is below all fixed_in thresholds; no update since Nov 2023.
- No CSP present — MV3 strict default applies, but CVE amplifier ×1.5 triggered (no CSP + medium CVE in DOM-manip lib) manifest content_security_policy is null; jquery is a DOM-manipulation lib matching the amplifier condition.
- Privacy policy is Google's generic account policy, not scoped to this extension store scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy pillar (v3.5 rule D).
- 31 months since last update — maintenance score 8.5 store Last updated November 21, 2023; falls in 24–36 month band.
- Description/permission mismatch: promises recording but lacks tabCapture/desktopCapture store description_promise.mismatches non-empty; is_shell_pattern=false.
- Featured by Google badge present — applied -2.0 Reputation discount store is_featured_by_google=true; no verified_publisher badge.
- No bad-host, affiliate, or monetization hits in threat_intel crx bad_host_hits, affiliate_hits, monetization_hits all empty.
- Operator cluster sibling_count=0; single-extension fingerprint, no cluster risk api compound sibling_count=0; dev_email sibling_count=0.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@3.1.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.1.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.1.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- storage low Stores user settings/preferences locally; low impact.
- scripting medium Allows injecting scripts into pages; scoped to activeTab so moderate risk.
- activeTab low Grants access to current tab on user action only; transient, low risk.
Pillar Scores
Permissions1.60
Reputation4.50
Network0.00
Webstore3.00
Maintenance8.50
Privacy10.00
Code Quality3.00
CVE Exposure4.50
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:36
Listing SHA
6a24185ed8bc…
Force block
— not fired
Score recovered
no
Elapsed
27.6s