Zight Screen Recorder, Screenshot App
ojnikmlgjpfiogeijjkpeakbedjhjcch
Risk Score
4.49
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- <all_urls> host permission combined with scripting allows content injection on every site visited.
- Privacy policy fetch failed (HTTP error); actual data handling terms unverifiable.
- No CSP on MV3 extension; new Function() constructor present in RecorderSettings bundle.
- Content script injected on mail.google.com; potential exposure of email content.
- No developer name listed; developer identity relies solely on zight.com domain.
Evidence
- host_permission_all_urls manifest <all_urls> host permission grants access to every site; paired with scripting.
- privacy_policy_fetch_failed api privacy_policy_classification.fetched==false due to fetch_error:HTTPError; scored +10.0.
- function_constructor_code_finding crx new Function() in RecorderSettings-bae20a28.js; +2.5 code quality.
- content_script_gmail manifest content_scripts_matches includes https://mail.google.com/*; email page access.
- no_csp manifest content_security_policy is null; MV3 default applies but no explicit restriction.
- no_developer_name store developer_name is empty string; identity relies on email domain only.
- description_promise_mismatch store Promises recording but lacks tabCapture/desktopCapture in manifest permissions.
- external_hosts_count crx 12 external JS hosts including pusher.com, analytics.zight.com, feross.org, github.com.
Permissions Breakdown
- activeTab low Grants access to current tab on user action; minimal risk.
- clipboardWrite medium Can write to clipboard; expected for screenshot/recorder tools.
- contextMenus low Adds right-click menu items; low standalone risk.
- notifications low Shows desktop notifications; low risk.
- offscreen low Offscreen document for background processing; reasonable for recorder.
- scripting medium Can inject scripts into pages; elevated but needed for screen capture.
- storage low Local extension storage; low risk.
- unlimitedStorage low Allows large local storage; expected for video/screenshot storage.
- <all_urls> (host_permission) high Broad host access across all sites; combined with scripting raises risk surface.
Pillar Scores
Permissions4.50
Reputation5.50
Network3.50
Webstore3.00
Maintenance1.50
Privacy10.00
Code Quality2.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:01
Listing SHA
6c22b2f484bf…
Force block
— not fired
Score recovered
no
Elapsed
23.3s