Screencastify - Screen Video Recorder
mmeijimgabbpbgpdklnllpncmdofkcpn
Risk Score
5.24
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- underscore@1.8.3 bundles critical CVE-2021-23358 (Arbitrary Code Execution) and high CVE-2026-27601 (DoS); not updated past fixed versions.
- Broad host permissions (<all_urls> + scripting) allow script injection into every page visited by 6M users.
- Privacy policy fetched but scope_extension==false with data_collection+third_party_sharing true — admits broad data sharing without scoping to this extension.
- 5 external JS hosts (unpkg.com, github.com, emscripten.org, vuejs.org, v3-migration.vuejs.org) create supply-chain exposure.
- No developer display name; rating 3.9 is below positive threshold for a 6M-install extension.
Evidence
- critical_cve crx underscore@1.8.3 has CVE-2021-23358 (ACE, critical); fixed in 1.12.1 — bundled version unfixed.
- high_cve crx underscore@1.8.3 has CVE-2026-27601 (DoS, high); fixed in 1.13.8 — bundled version unfixed.
- broad_host_permissions manifest <all_urls> + *://*/* paired with scripting permission enables page-wide script injection.
- privacy_policy_scope_mismatch api Policy fetched (28k chars) but scope_extension=false, data_collection=true, third_party_sharing=true.
- external_js_hosts crx 5 distinct external hosts referenced: unpkg.com, github.com, emscripten.org, vuejs.org, v3-migration.vuejs.org.
- no_developer_name store developer_name is empty string; reduces accountability signal.
- featured_by_google store is_featured_by_google=true; partially mitigates reputation concerns.
- content_scripts_google_drive_mail manifest Content scripts run on mail.google.com, drive.google.com, outlook.live.com — sensitive data surfaces.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2020-36632 | flat@unknown | critical | 1.6.2 | flat vulnerable to Prototype Pollution |
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- alarms low Scheduling only, no data access.
- storage low Local extension data persistence.
- tabs medium Can read tab URLs and titles across sessions.
- activeTab medium Access to current tab content on user action.
- offscreen low Offscreen document for media processing; low standalone risk.
- scripting high Injects scripts into pages; combined with <all_urls> is high risk.
- unlimitedStorage low Storage quota only; no extra data access.
- tabCapture high Captures audio/video of any tab — core screen recorder function but high capability.
- desktopCapture high Captures entire desktop screen and audio.
- webNavigation medium Observes navigation events across tabs.
- notifications low Display notifications only.
- system.display low Read display metadata for recording config.
- <all_urls> high Broad host access enabling scripting on every site.
- *://*/* high Redundant broad host permission amplifying <all_urls> reach.
Pillar Scores
Permissions6.50
Reputation4.50
Network3.00
Webstore2.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure7.00
Scoring History
| %22fsssiedxa sssiedx | 5.10 | Medium | review | 2026-08-14 |
| "fsssiedxa'sssiedx | 4.44 | Medium | review | 2026-08-14 |
| fsssiedxa"sssiedx | 4.02 | Medium | review | 2026-08-14 |
| "fsssiedxa xx psssiedx | 4.47 | Medium | review | 2026-08-08 |
| %27fsssiedxa$"sssiedx | 5.23 | Medium | block | 2026-08-08 |
| 5.21 | Medium | review | 2026-08-08 | |
| fsssiedxa$'sssiedx | 5.37 | Medium | block | 2026-08-08 |
| "fsssiedxgfdsaxax><!--></ScRiPt>asddsssiedx | 5.32 | Medium | review | 2026-08-07 |
| <fsssiedxf'sssiedx | 5.14 | Medium | review | 2026-08-07 |
| <fsssiedx{$"sssiedx | 4.15 | Medium | review | 2026-08-07 |
| <fsssiedxi$'sssiedx | 5.34 | Medium | review | 2026-08-07 |
| <fsssiedx{ xx psssiedx | 5.24 | Medium | review | 2026-08-04 |
| xx pfsssiedxi$'sssiedx | 4.37 | Medium | review | 2026-08-04 |
| 'fsssiedxi$"sssiedx | 5.92 | Medium | review | 2026-08-04 |
| "fsssiedxi'sssiedx | 4.13 | Medium | review | 2026-08-04 |
| fsssiedxi<sssiedx | 5.62 | Medium | review | 2026-08-04 |
| <fsssiedxf$"sssiedx | 5.26 | Medium | review | 2026-08-04 |
| <fsssiedxi'sssiedx | 5.34 | Medium | review | 2026-08-04 |
| <fsssiedxa"sssiedx | 3.51 | Low | review | 2026-08-04 |
| <fsssiedxi$"sssiedx | 5.73 | Medium | block | 2026-07-29 |
| <fsssiedx{fdsaxax><!--></ScRiPt>asddsssiedx | 5.13 | Medium | review | 2026-07-29 |
| fsssiedx<sssiedx | 5.24 | Medium | review | 2026-07-29 |
| xx pfsssiedxh$"sssiedx | 5.16 | Medium | review | 2026-07-29 |
| %27fsssiedxh"sssiedx | 4.56 | Medium | review | 2026-07-29 |
| 'fsssiedxh$'sssiedx | 5.62 | Medium | review | 2026-07-29 |
| <fsssiedxh sssiedx | 5.61 | Medium | review | 2026-07-29 |
| <fsssiedxh$"sssiedx | 5.14 | Medium | review | 2026-07-29 |
| %22fsssiedxa$"sssiedx | 6.88 | High | block | 2026-07-28 |
| fsssiedxa$"sssiedx | 5.27 | Medium | review | 2026-07-28 |
| <fsssiedxa xx psssiedx | 5.37 | Medium | review | 2026-07-28 |
| <fsssiedxa'sssiedx | 4.08 | Medium | review | 2026-07-28 |
| <fsssiedxa$"sssiedx | 4.12 | Medium | review | 2026-07-28 |
| <fsssiedxa$'sssiedx | 5.34 | Medium | review | 2026-07-28 |
| <fsssiedxa'sssiedx | 5.06 | Medium | review | 2026-07-28 |
| <fsssiedxa"sssiedx | 3.63 | Low | review | 2026-07-28 |
| fsssiedxa<sssiedx | 5.54 | Medium | review | 2026-07-28 |
| fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 5.18 | Medium | review | 2026-07-28 |
| sssieddrubricxsx | 5.27 | Medium | review | 2026-07-28 |
| v3.6 | 5.24 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:56
Listing SHA
c33bfb44e056…
Force block
— not fired
Score recovered
no
Elapsed
27.1s