Screenshot to Notion & Annotate
lkedoimppfegdfhggggbfohioeafkmlp
Risk Score
3.93
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- cookies + <all_urls>: can read session cookies from any site visited.
- No CSP on MV3 extension; scripting + <all_urls> allows broad page manipulation.
- Privacy policy fetched but does not scope to this extension or disclose data collection.
- Last updated 17 months ago; no active maintenance signal.
- new Function() constructor found in popup.js; limited obfuscation risk but non-zero.
Evidence
- cookies + <all_urls> manifest cookies permission with <all_urls> host permission enables session theft from any site.
- no CSP crx content_security_policy is null; no script-src hardening despite scripting + broad hosts.
- privacy policy inadequate api Policy fetched (1002 chars), scope_extension=false, data_collection=false; too brief, not extension-scoped.
- verified_publisher + featured store Verified publisher and featured badge; reputation floor applied at 2.0.
- function_constructor crx new Function() in js/popup.js; likely bundler globalThis shim, low-severity but flagged.
- stale update store Last updated January 2024 (~17 months); maintenance score +3.5.
- external JS hosts crx Contacts fonts.googleapis.com, tailwindcss.com, us-central1-markuphero.cloudfunctions.net.
- no CVEs crx cve_findings_raw empty; no bundled vulnerable libraries detected.
Permissions Breakdown
- storage low Stores extension settings/data locally.
- clipboardWrite medium Writes screenshot data to clipboard; medium risk, function-appropriate.
- activeTab low Scoped to current tab on user action.
- tabs medium Can read tab URLs/titles across browser; moderate risk.
- desktopCapture medium Captures screen content; core to screenshot function but sensitive.
- scripting medium Can inject scripts into pages; paired with <all_urls> increases reach.
- cookies high Access to cookies on all domains; combined with <all_urls> is high risk.
- <all_urls> (host_permission) high Broad host access paired with cookies and scripting is highest-risk combo.
- https://markuphero.com/ low Dev-owned backend for core functionality.
- https://storage.googleapis.com/ low Google Cloud Storage for asset/image hosting.
- https://api.notion.com/ low Notion API for stated screenshot-to-Notion feature.
Pillar Scores
Permissions5.10
Reputation2.00
Network2.00
Webstore0.00
Maintenance3.50
Privacy9.00
Code Quality2.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-15 14:25
Listing SHA
f52dcdfc5df6…
Force block
— not fired
Score recovered
no
Elapsed
24.6s