Video Screenshot
ppkojackhibeogijphhfnamhemklmial
Risk Score
4.29
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Brand impersonation: mentions YouTube, Netflix, Disney+ without verified ownership — confirmed by brand_mention.is_impersonation.
- Privacy policy fetched (171 chars) but does not scope to this extension; no retention clause — functionally inadequate.
- No CSP (MV3 default provides some protection, but 9 external JS hosts contacted including Firebase Cloud Functions).
- Install URL hijack: onInstalled opens videoscreenshot.app/welcome — install redirect to third-party promotional page.
- Description promises 'recording' but lacks tabCapture/desktopCapture — permission/promise mismatch flagged.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; brands: youtube, netflix, disney; confirmed_owner=false.
- install_url_hijack crx install_url_hijack=true; target=https://videoscreenshot.app/welcome — opens 3rd-party page on install.
- privacy_policy_inadequate api Policy length=171 chars; scope_extension=false, data_collection=false, retention=false, third_party_silence=true.
- broad_host_access manifest host_permissions=[<all_urls>] + content_scripts_matches=[<all_urls>]; JS injected on every page.
- external_hosts_9 crx 9 external hosts including us-central1-video-screenshot.cloudfunctions.net, firebase, google-analytics.
- description_mismatch store Promises recording but lacks tabCapture/desktopCapture permission per description_promise.mismatches.
- verified_publisher_featured store verified_publisher=true, is_featured_by_google=true; partial trust discount applied.
- monetization_telemetry crx google-analytics.com in js_external_hosts; classified telemetry-tier only — no bad/affiliate hosts.
Permissions Breakdown
- downloads medium Allows saving files to disk; expected for screenshot/capture tool.
- storage low Local data persistence; low risk in isolation.
- <all_urls> (host_permissions) high Content scripts injected into every site; broad reach across all browsing.
- <all_urls> (content_scripts_matches) high JS runs on all pages; combined with host_permission doubles broad-access risk surface.
Pillar Scores
Permissions5.50
Reputation4.50
Network3.50
Webstore6.00
Maintenance0.00
Privacy9.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:06
Listing SHA
2b4473ad0d73…
Force block
— not fired
Score recovered
no
Elapsed
21.7s