Awesome Screen Recorder & Screenshot
nlipoenfbbikpbjkfpfillcgkoblgpmj
Risk Score
4.92
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy fetched but scope_extension=false AND data_collection+third_party_sharing=true: admits broad data collection without scoping to this extension.
- cookies + <all_urls> + scripting: high-capability combo enabling cross-site data access and script injection on every visited page.
- desktopCapture + tabCapture: can silently record full desktop and any browser tab.
- jquery@3.4.0 bundled with CVE-2020-11022/11023 (XSS); multiple function_constructor and innerHTML DOM-XSS sinks in content scripts.
- No developer name listed; privacy policy does not scope data handling to this extension despite confirmed third-party sharing.
Evidence
- cookies+<all_urls>+scripting manifest High-capability triple: cookies, scripting, <all_urls> host_permissions and content_scripts on http://*/* https://*/*.
- privacy_policy_scope_miss crx Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (D rule).
- cve_jquery_3.4.0 crx jquery@3.4.0 bundles CVE-2020-11022 and CVE-2020-11023 (moderate XSS); fixed_in 3.5.0.
- function_constructor_multi crx new Function() constructor found in 8 bundle files including pageWorld.bundle.js with non-trivial wrapper usage.
- dom_innerHTML_sinks crx innerHTML user-controlled sinks in 4 bundle files including gmailContent.bundle.js and content.bundle.js.
- sandbox_csp_remote_scripts manifest Sandbox CSP allows script-src ssl.google-analytics.com, www.google-analytics.com, connect.facebook.net, platform.twitter.com.
- verified_publisher+featured store verified_publisher=true, is_featured_by_google=true; reputation floor applied at 2.0.
- monetization_telemetry_only crx monetization_hits: Google Analytics only (telemetry tier); no affiliate or bad hosts.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2020-11022 | jquery@3.4.0 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.4.0 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- tabs medium Access to tab URLs and metadata across all tabs.
- power low Prevents device sleep; low privacy impact.
- storage low Local extension data storage.
- unlimitedStorage low Extended local storage for recordings/screenshots.
- desktopCapture high Can capture full desktop screen content.
- tabCapture high Can capture audio/video of any tab.
- cookies high Read/write cookies across origins; paired with <all_urls>.
- activeTab low Scoped to user-activated tab only.
- contextMenus low Adds right-click menu items.
- scripting high Can inject scripts into pages; paired with <all_urls>.
- offscreen low Offscreen document for media processing.
- alarms low Background scheduling; minimal risk.
- <all_urls> high Broad host access enabling script injection and cookie access on all sites.
Pillar Scores
Permissions7.00
Reputation2.00
Network3.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure3.00
Scoring History
| <fsssiedxa"sssiedx | 4.39 | Medium | review | 2026-08-19 |
| <fsssiedxa'sssiedx | 4.03 | Medium | review | 2026-08-19 |
| <fsssiedxa | 3.06 | Low | review | 2026-08-13 |
| <fsssiedxa"sssiedx | 3.01 | Low | review | 2026-08-13 |
| <fsssiedxa'sssiedx | 3.01 | Low | review | 2026-08-13 |
| <fsssiedxa$'sssiedx | 3.06 | Low | review | 2026-08-13 |
| <fsssiedxa xx psssiedx | 4.04 | Medium | review | 2026-08-13 |
| fsssiedxa<sssiedx | 4.14 | Medium | review | 2026-08-13 |
| <fsssiedxa$"sssiedx | 4.03 | Medium | review | 2026-08-09 |
| fsssiedx<sssiedx | 4.05 | Medium | review | 2026-08-09 |
| sssieddrubricxsx | 4.19 | Medium | review | 2026-07-31 |
| v3.6 | 4.92 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:59
Listing SHA
afbd66f5a953…
Force block
— not fired
Score recovered
no
Elapsed
34.9s