Is "Take and resize browser screenshots" on Chrome Web Store Safe to Install?

[email protected] · chrome · v0.0.9

USE CASE: You are preparing documentation of a web tool. You need screenshots of the browser window as is. Everything you see, namely the URL in the address bar, opened menus and tooltips triggered by mouse over events, must be visible in the screenshots. A screenshot should be taken, saved and copied to the clipboard in one click. You could do that with Greenshot if having to select the region for each screenshot does not annoy you. With the Snipping Tool you need to click a bit more to save the file. What if the screenshots have to be resized to a specified size to be uploaded somewhere? For example, imagine you are preparing 1280x800 screenshots required for publishing an extension in the Web Store. The 1280x800 screenshots illustrating this extension were taken with this extension. HOW TO USE: - Click the icon to select the screen with the browser window to be captured. The icon becomes green, the extension is ready to take screenshots of the selected screen. - A notification bar appears at the bottom. It is an independent browser window. Click Hide to minimise the bar window. - Open a web page in the browser running in the selected screen.The browser window can be maximized or minimized. The extension captures the screen region of the browser window in which the icon has been clicked. - Click the icon to take a screenshot. Each time you click, the screenshot is downloaded and copied to the clipboard. The file name of the downloaded screenshot is the URL of the page where the icon was clicked. - Keep taking screenshots. Maximize, minimize and move the browser window. - To inactivate the extension, first maximise the screen sharing notification bar by clicking the last browser window, then click the blue Stop sharing button. OPTIONS: The extension works without any additional configuration. If needed, the screenshots can be resized before saving and saved as png or jpeg files. Capture of the screen can be delayed if you need to capture a browser menu or HTML or browser tooltip triggered by a mouseover event. The options can be accessed by right-clicking the extension’s icon and then clicking the Options IMPORTANT NOTE: Regardless of the tool you use, you can capture HTML tooltips, or browser tooltips or menus, only if you capture a screen. That is a constraint by the operating system. Tooltips and menus cannot be captured in a window or tab display surface. You can read about the limitations of the Screen Capture API here https://medium.com/@marian-caikovski/beware-of-the-tab-and-window-display-surfaces-they-are-defective-87a5e428a731 HOW THIS EXTENSION COMPARES TO ALTERNATIVES: - It is simple to use because it is designed for one purpose - documentation of web applications. - Its user interface is the icon and the options accessible on right-clicking the icon. It has no cumbersome popups with pointless options. One click - one file on the disk and in the clipboard - It is free and open source

Risk Assessment

Analyzed
53.35
out of 100
MEDIUM

39 security findings detected across all analyzers

Chrome extension requesting 6 permissions

Severity Breakdown

0
Critical
23
High
16
Medium
0
Low
0
Info

Finding Categories

23
Malware Signatures
5
Network
11
IoC Indicators

YARA Rules Matched

7 rules(23 hits)
postinstall file manipulation postinstall file download postinstall network communication postinstall system command postinstall crypto operations postinstall obfuscation postinstall environment access

Requested Permissions

6 permissions
downloads

Manage, modify, and monitor downloads

High
activeTab
Medium
scripting
Low
storage
Low
offscreen
Low
clipboardWrite
Low

About This Extension

USE CASE: You are preparing documentation of a web tool. You need screenshots of the browser window as is. Everything you see, namely the URL in the address bar, opened menus and tooltips triggered by mouse over events, must be visible in the screenshots. A screenshot should be taken, saved and copied to the clipboard in one click. You could do that with Greenshot if having to select the region for each screenshot does not annoy you. With the Snipping Tool you need to click a bit more to save the file. What if the screenshots have to be resized to a specified size to be uploaded somewhere? For example, imagine you are preparing 1280x800 screenshots required for publishing an extension in the Web Store. The 1280x800 screenshots illustrating this extension were taken with this extension. HOW TO USE: - Click the icon to select the screen with the browser window to be captured. The icon becomes green, the extension is ready to take screenshots of the selected screen. - A notification bar appears at the bottom. It is an independent browser window. Click Hide to minimise the bar window. - Open a web page in the browser running in the selected screen.The browser window can be maximized or minimized. The extension captures the screen region of the browser window in which the icon has been clicked. - Click the icon to take a screenshot. Each time you click, the screenshot is downloaded and copied to the clipboard. The file name of the downloaded screenshot is the URL of the page where the icon was clicked. - Keep taking screenshots. Maximize, minimize and move the browser window. - To inactivate the extension, first maximise the screen sharing notification bar by clicking the last browser window, then click the blue Stop sharing button. OPTIONS: The extension works without any additional configuration. If needed, the screenshots can be resized before saving and saved as png or jpeg files. Capture of the screen can be delayed if you need to capture a browser menu or HTML or browser tooltip triggered by a mouseover event. The options can be accessed by right-clicking the extension’s icon and then clicking the Options IMPORTANT NOTE: Regardless of the tool you use, you can capture HTML tooltips, or browser tooltips or menus, only if you capture a screen. That is a constraint by the operating system. Tooltips and menus cannot be captured in a window or tab display surface. You can read about the limitations of the Screen Capture API here https://medium.com/@marian-caikovski/beware-of-the-tab-and-window-display-surfaces-they-are-defective-87a5e428a731 HOW THIS EXTENSION COMPARES TO ALTERNATIVES: - It is simple to use because it is designed for one purpose - documentation of web applications. - Its user interface is the icon and the options accessible on right-clicking the icon. It has no cumbersome popups with pointless options. One click - one file on the disk and in the clipboard - It is free and open source

Detailed Findings

28 total

YARA Rule Matches

7 rules

Indicators of Compromise

Network indicators, suspicious strings, and potential IoCs extracted during analysis

URLs
4
IP Addresses
1
Domains
7
Strings
11

All Indicators · 11

Domain
detected Domain: medium.com

XIOC detected Domain: medium.com

extracted_from_files

URL
detected URL: https://clients2.google.com/service/update2/crx

XIOC detected URL: https://clients2.google.com/service/update2/crx

extracted_from_files

URL
detected URL: https://chromewebstore.google.com/detail/apnblgjgaahmbdkcpepigfcahccpadjl/support

XIOC detected URL: https://chromewebstore.google.com/detail/apnblgjgaahmbdkcpepigfcahccpadjl/support

extracted_from_files

URL
detected URL: https://chromewebstore.google.com/detail/take-and-resize-browser-s/apnblgjgaahmbdkcpepigfcahccpadjl

XIOC detected URL: https://chromewebstore.google.com/detail/take-and-resize-browser-s/apnblgjgaahmbdkcpepigfcahccpadjl

extracted_from_files

Domain
detected Domain: clients2.google.com

XIOC detected Domain: clients2.google.com

extracted_from_files

Domain
detected Domain: el.name

XIOC detected Domain: el.name

extracted_from_files

Domain
detected Domain: e.target

XIOC detected Domain: e.target

extracted_from_files

Domain
detected Domain: chromewebstore.google.com

XIOC detected Domain: chromewebstore.google.com

extracted_from_files

Domain
detected Domain: chrome.downloads.download

XIOC detected Domain: chrome.downloads.download

extracted_from_files

Domain
detected Domain: chrome.runtime.id

XIOC detected Domain: chrome.runtime.id

extracted_from_files

URL
detected URL: https://medium.com/@marian-caikovski/using-javascript-modules-in-content-scripts-and-extension-service-workers-e60e97979326

XIOC detected URL: https://medium.com/@marian-caikovski/using-javascript-modules-in-content-scripts-and-extension-service-workers-e60e97979326

extracted_from_files

Security Analysis Summary

Security Analysis Overview

Take and resize browser screenshots is a Chrome Web Store extension published by [email protected]. Version 0.0.9 has been analyzed by the Risky Plugins security platform, receiving a risk score of 53.35/100 (MEDIUM risk) based on 39 security findings.

Risk Assessment

This extension presents moderate security risk. Several findings were detected that may warrant attention. Users should carefully review the permissions and findings before installation.

Findings Breakdown

  • High: 23 finding(s)
  • Medium: 16 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

Take and resize browser screenshots is published by [email protected] on the Chrome Web Store marketplace. The extension has approximately 18 users.

Recommendation

Exercise caution with this extension. Review the detailed findings and ensure the requested permissions align with the extension's stated functionality before installation.

Frequently Asked Questions