Screen Recorder & Screenshot App for Chrome | Scrnli
ijejnggjjphlenbhmjhhgcdpehhacaal
Risk Score
4.71
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- debugger_attach confirmed in background.js: full tab inspection capability with <all_urls> host access.
- Free-webmail dev (gmail) with no developer name; verified publisher but identity accountability is limited.
- Privacy policy fetched but scope_extension==false and no retention disclosed; does not describe extension-specific data.
- No CSP present (MV3 default policy applies but no explicit restriction); multiple new Function() calls across 5 files.
- Broad host permissions (*://*/*) paired with scripting and debugger create high-capability attack surface if compromised.
Evidence
- debugger_attach crx background.js calls chrome.debugger.attach() on active tab; debugger permission declared.
- free_webmail_dev store developer_email=roslabikeryma@gmail.com; developer_name empty; brand domain scrnli.com not email domain.
- verified_publisher store verified_publisher=true and is_featured_by_google=true; reduces reputation risk.
- privacy_policy_scope api Policy fetched (535 chars) but scope_extension=false, data_collection=false, retention=false.
- broad_host_access manifest host_permissions=[*://*/*] and content_scripts include <all_urls>; full web access.
- function_constructor_multi crx new Function() detected in 5 files; pattern includes user-serialized clipTo in fabric.js canvas lib.
- no_csp manifest content_security_policy=null; MV3 default applies but no explicit script-src restriction declared.
- install_count store 1,000,000 installs with 4.7 rating; high reach amplifies any future compromise.
Permissions Breakdown
- storage low Standard local data storage.
- activeTab medium Access to current tab on user action; limited scope.
- tabCapture high Captures tab audio/video stream; core to screen recorder but powerful.
- unlimitedStorage low Needed for large recording files.
- desktopCapture high Captures full desktop or window; high sensitivity but matches stated function.
- scripting high Can inject JS into pages; paired with <all_urls> host permission.
- offscreen low Background processing of media; low standalone risk.
- debugger high Attaches debugger to tabs; confirmed use in code; very powerful capability.
- *://*/* high Broad host access across all URLs; amplifies scripting and debugger risk.
Pillar Scores
Permissions7.00
Reputation4.50
Network2.00
Webstore2.00
Maintenance0.00
Privacy9.00
Code Quality5.50
CVE Exposure0.00
Scoring History
| fsssiedxn7ce06d10za"n7ce06d10zsssiedx | 4.55 | Medium | review | 2026-09-10 |
| sssiedn6e7d1c53dp727562726963xsx | 4.84 | Medium | review | 2026-09-10 |
| sssiedn7cb24755dp727562726963xsx | 4.73 | Medium | review | 2026-09-06 |
| sssiedn441533cadp727562726963xsx | 5.04 | Medium | review | 2026-08-30 |
| fsssiedxa xx psssiedx | 4.21 | Medium | review | 2026-08-09 |
| sssieddrubricxsx | 4.47 | Medium | review | 2026-08-09 |
| v3.6 | 4.71 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:43
Listing SHA
f2d0580014d3…
Force block
— not fired
Score recovered
no
Elapsed
29.8s