Take Webpage Screenshots Entirely - FireShot
mcbpblocgmgfnpjjppndjkmgjaogfceg
Risk Score
4.54
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy admits data collection and third-party sharing but is not scoped to this extension (generic policy trigger).
- nativeMessaging with unrecognized publisher allows arbitrary native-app code execution on host OS.
- jQuery 3.3.1 bundled with 3 medium-severity CVEs (XSS); not updated to fixed version 3.5.0.
- Dynamic script loading (script_src_dynamic) and Function constructor found in code; elevated injection risk.
- 10 distinct external JS hosts contacted including screenshot-program.com; broader than expected for a screenshot tool.
Evidence
- native_messaging_unrecognized_publisher crx nativeMessaging declared; native_messaging_check.publisher_recognized == false. Allows OS-level code execution.
- privacy_policy_generic_with_third_party_sharing crx Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy pillar.
- cve_jquery_3_3_1_moderate_x3 crx jquery@3.3.1 has CVE-2019-11358, CVE-2020-11022, CVE-2020-11023 (moderate XSS); fixed_in 3.5.0.
- code_script_src_dynamic crx scripts/enc/fsWorker.js creates dynamic <script src=> element; enables remote code load in worker context.
- code_function_constructor crx scripts/vue/vue-index.js uses new Function(); elevated eval-equivalent risk.
- external_hosts_diverse crx 10 distinct external JS hosts: api.inboxsdk.com, screenshot-program.com, ssl.getfireshot.com and 7 others.
- verified_publisher_featured store Verified publisher + Google Featured badge; discounts applied but capped due to privacy policy concerns.
- description_promise_mismatch store Description promises recording but lacks tabCapture/desktopCapture permissions.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@3.3.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- storage low Stores extension settings locally; minimal risk.
- alarms low Schedules tasks; low standalone risk.
- scripting medium Injects scripts into tabs; necessary for screenshot capture but elevates capability.
- activeTab medium Accesses current tab content on user action; scoped but grants page access.
- nativeMessaging high Communicates with native companion app; publisher not recognized, high-impact channel.
- contextMenus low Adds right-click menu items; no data access.
Pillar Scores
Permissions5.50
Reputation2.00
Network3.50
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure3.00
Scoring History
| sssieddrubricxsx | 4.37 | Medium | review | 2026-08-09 |
| v3.6 | 4.54 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:54
Listing SHA
51fa09fecb1d…
Force block
— not fired
Score recovered
no
Elapsed
31.0s