Scrolling screenshot tool & screen capture
mfpiaehgjbbfednooihadalhehabhcjo
Risk Score
5.14
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy fetched but scope_extension=false with data_collection+third_party_sharing=true — policy admits broad data collection without extension-specific scoping (+10.0 privacy).
- Stale extension: 35 months since last update with known CVEs and broad host access — triple-stale fingerprint applies.
- jQuery 3.4.0 bundled with 2 moderate XSS CVEs (CVE-2020-11022, CVE-2020-11023); fix available at 3.5.0.
- Multiple innerHTML DOM-XSS sinks in content scripts running on all URLs, plus new Function() usage.
- Uninstall URL redirects to awesomescreenshot.com domain; analytics hosts (Google Analytics) in CSP sandbox script-src.
Evidence
- privacy_policy_admits_collection_and_sharing_no_extension_scope api scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 rule D).
- triple_stale_fingerprint store months_since_update=35 (>24mo), cve_findings_raw non-empty, manifest_version=3 → +2.0 webstore (v2 fix c).
- cve_jquery_3.4.0_moderate_x2 crx CVE-2020-11022 + CVE-2020-11023 in jquery@3.4.0; fixed_in 3.5.0. 2 medium CVEs → +2.0 CVE pillar.
- dom_sink_innerhtml_userctrl_multiple crx 6 innerHTML sink findings across content/bundle scripts; cve_findings_raw non-empty → each triggers +2.0 FIX B path.
- function_constructor_usage crx new Function() constructor in annotate/feedback/option/dragresize bundles → +2.5 code quality.
- uninstall_url_hijack manifest chrome.runtime setUninstallURL → awesomescreenshot.com/uninstall — developer-owned domain, not third-party.
- monetization_hits_telemetry_only api Google Analytics (ssl/www.google-analytics.com) in threat_intel.monetization_hits; telemetry-tier only → +1.0 webstore.
- verified_publisher_featured store verified_publisher=true + is_featured_by_google=true; discount capped at -1.0 due to monetization_hits (v3.5 rule E).
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2020-11022 | jquery@3.4.0 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.4.0 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- storage low Standard local data persistence.
- unlimitedStorage low Needed to store large screenshots locally.
- desktopCapture high Can capture full desktop/tab pixels including sensitive content.
- activeTab medium Access to current tab content on user action.
- scripting medium Can inject JS into pages; paired with <all_urls> broadens reach.
- <all_urls> (host_permissions) high Content scripts run on every http/https page, wide attack surface.
Pillar Scores
Permissions5.50
Reputation2.00
Network3.50
Webstore5.50
Maintenance8.50
Privacy10.00
Code Quality5.00
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:55
Listing SHA
8d77bbbce38d…
Force block
— not fired
Score recovered
no
Elapsed
37.0s