Page capture screenshot tool-ThisShot
ojobnnfifncmgnjnbdlmkmhecaccjapp
Risk Score
6.27
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- 38-month stale update (>36mo) with 10K installs on an abandoned gmail-dev extension — prime acquisition target.
- Privacy policy is Google's own generic policy (scope_extension=false, admits data collection + 3rd-party sharing): scores 10.0.
- Content script injected on *://*/* gives broad page-content reach across every site visited.
- Developer is anonymous gmail address with no dev name or verified business identity.
- No CSP on MV3 extension contacting third-party addonx.net with content scripts on all URLs.
Evidence
- maintenance_stale store Last updated April 2023; 38 months since update — zombie booster applies (>36mo + 10K installs).
- privacy_generic_google_policy store Policy is myaccount.google.com/privacypolicy — scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5-D).
- dev_identity_weak store developer_name is empty; developer_email is free webmail (gmail). No business domain.
- content_scripts_all_urls manifest content_scripts_matches includes *://*/* — injected into every page user visits.
- host_permission_addonx manifest host_permissions include addonx.net — third-party domain, no threat hits but unverified operator.
- no_csp crx content_security_policy is null; MV3 default is strict but no explicit CSP declared.
- description_promise_mismatch store description promises recording but lacks tabCapture/desktopCapture permissions.
- verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; but invariant 0c caps discount to -1.0 due to stale >18mo.
Permissions Breakdown
- tabs medium Access to tab URLs and metadata; moderate risk for screenshot tool.
- storage low Local preference/data storage; standard low risk.
- unlimitedStorage low Extended local storage; low risk, expected for screenshot archiving.
- activeTab low Scoped to user-invoked tab only; low risk.
- scripting medium Inject scripts into pages; medium risk without broad host access.
- host:http://addonx.net/* medium Explicit host to third-party addonx.net; unknown operator.
- host:https://addonx.net/* medium Same as above over HTTPS.
- content_scripts:*://*/* high Content script on every page — broad reach beyond screenshot function.
Pillar Scores
Permissions4.50
Reputation7.00
Network4.50
Webstore5.50
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:01
Listing SHA
6cca52414dda…
Force block
— not fired
Score recovered
no
Elapsed
25.7s