Screenshot - Webpage Screen Capture
okkffdhbfplmbjblhgapnchjinanmnij
Risk Score
4.46
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy admits data collection and third-party sharing but is not scoped to this extension — worst-case disclosure.
- Developer uses free Gmail address with no developer name; identity unverifiable despite verified publisher badge.
- new Function() constructor found in 7 JS files including content script sm.js — dynamic code execution risk.
- Content scripts injected on <all_urls> combined with tabCapture grants full-page and screen capture access on every site.
- install_url_hijack opens third-party imageEditor URL on install; unexpected redirect to external resource.
Evidence
- privacy_policy_admits_collection_and_sharing_no_scope api policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → Privacy pillar +10.0 (D rule).
- developer_identity_weak store developer_name empty; email johnsonalma781@gmail.com (free webmail). Verified publisher badge present but identity thin.
- function_constructor_multiple_files crx new Function() in 7 files including content/sm.js; dynamic code execution risk in broad host-permission context.
- install_url_hijack manifest install_url_target=imageEditor/imageEditor.html?nanoId= opens external URL on install — v3 webstore signal.
- broad_host_permissions manifest <all_urls> host_permissions + content_scripts; justified by Screenshot category but still high-reach.
- js_external_hosts_documentation crx js_external_hosts: github.com, js.foundation, mozilla.github.io, sizzlejs.com — likely license refs, not runtime CDN.
- verified_publisher_featured store verified_publisher=true, is_featured_by_google=true; partially offsets reputation concern.
- cve_clean api cve_findings_raw empty; jquery 3.7.0 bundled has no flagged CVEs. CVE pillar = 0.0.
Permissions Breakdown
- storage low Stores settings/state locally; standard for screenshot tools.
- tabCapture high Captures full tab video/audio stream; core but powerful capability.
- tabs medium Reads tab URLs and metadata; needed for screenshot context.
- downloads medium Saves captured images to disk; expected for screenshot extension.
- offscreen low Allows off-screen document for rendering; MV3 pattern.
- <all_urls> (host) high Content scripts injected on every site; broad reach for capture.
Pillar Scores
Permissions4.50
Reputation5.50
Network2.00
Webstore2.00
Maintenance3.50
Privacy10.00
Code Quality2.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 07:57
Listing SHA
58e26211cb46…
Force block
— not fired
Score recovered
no
Elapsed
—