Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Zight Screen Recorder, Screenshot App

ojnikmlgjpfiogeijjkpeakbedjhjcch
Risk Score
4.49
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Screenshot
Installs 80,000
Rating 4.5
Last updated 2025-11-22 (7 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@zight.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • <all_urls> host permission combined with scripting allows content injection on every site visited.
  • Privacy policy fetch failed (HTTP error); actual data handling terms unverifiable.
  • No CSP on MV3 extension; new Function() constructor present in RecorderSettings bundle.
  • Content script injected on mail.google.com; potential exposure of email content.
  • No developer name listed; developer identity relies solely on zight.com domain.

Evidence

  • host_permission_all_urls manifest <all_urls> host permission grants access to every site; paired with scripting.
  • privacy_policy_fetch_failed api privacy_policy_classification.fetched==false due to fetch_error:HTTPError; scored +10.0.
  • function_constructor_code_finding crx new Function() in RecorderSettings-bae20a28.js; +2.5 code quality.
  • content_script_gmail manifest content_scripts_matches includes https://mail.google.com/*; email page access.
  • no_csp manifest content_security_policy is null; MV3 default applies but no explicit restriction.
  • no_developer_name store developer_name is empty string; identity relies on email domain only.
  • description_promise_mismatch store Promises recording but lacks tabCapture/desktopCapture in manifest permissions.
  • external_hosts_count crx 12 external JS hosts including pusher.com, analytics.zight.com, feross.org, github.com.

Permissions Breakdown

  • activeTab low Grants access to current tab on user action; minimal risk.
  • clipboardWrite medium Can write to clipboard; expected for screenshot/recorder tools.
  • contextMenus low Adds right-click menu items; low standalone risk.
  • notifications low Shows desktop notifications; low risk.
  • offscreen low Offscreen document for background processing; reasonable for recorder.
  • scripting medium Can inject scripts into pages; elevated but needed for screen capture.
  • storage low Local extension storage; low risk.
  • unlimitedStorage low Allows large local storage; expected for video/screenshot storage.
  • <all_urls> (host_permission) high Broad host access across all sites; combined with scripting raises risk surface.

Pillar Scores

Permissions4.50
Reputation5.50
Network3.50
Webstore3.00
Maintenance1.50
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:01
Listing SHA 6c22b2f484bf…
Force block — not fired
Score recovered no
Elapsed 23.3s