Screen Recorder

Screen Recorder

ID: bgnpgpfjdpmgfdegmmjdbppccdhjhdpe

Supported Languages

๐Ÿ‡ช๐Ÿ‡นAmharic
๐Ÿ‡ธ๐Ÿ‡ฆArabic
๐Ÿ‡ง๐Ÿ‡ฉBengali
๐Ÿ‡ง๐Ÿ‡ทBrazilian Portuguese
๐Ÿ‡ฌ๐Ÿ‡งBritish English
๐Ÿ‡ง๐Ÿ‡ฌBulgarian
๐Ÿ‡ช๐Ÿ‡ธCatalan
๐Ÿ‡จ๐Ÿ‡ณChinese (Simplified)
๐Ÿ‡น๐Ÿ‡ผChinese (Traditional)
๐Ÿ‡ญ๐Ÿ‡ทCroatian
๐Ÿ‡จ๐Ÿ‡ฟCzech
๐Ÿ‡ฉ๐Ÿ‡ฐDanish
๐Ÿ‡ณ๐Ÿ‡ฑDutch
๐Ÿ‡บ๐Ÿ‡ธEnglish
๐Ÿ‡ช๐Ÿ‡ชEstonian
๐Ÿ‡ต๐Ÿ‡ญFilipino
๐Ÿ‡ซ๐Ÿ‡ฎFinnish
๐Ÿ‡ซ๐Ÿ‡ทFrench
๐Ÿ‡ฉ๐Ÿ‡ชGerman
๐Ÿ‡ฌ๐Ÿ‡ทGreek
๐Ÿ‡ฎ๐Ÿ‡ณGujarati
๐Ÿ‡ฎ๐Ÿ‡ฑHebrew
๐Ÿ‡ฎ๐Ÿ‡ณHindi
๐Ÿ‡ญ๐Ÿ‡บHungarian
๐Ÿ‡ฎ๐Ÿ‡ฉIndonesian
๐Ÿ‡ฎ๐Ÿ‡นItalian
๐Ÿ‡ฏ๐Ÿ‡ตJapanese
๐Ÿ‡ฎ๐Ÿ‡ณKannada
๐Ÿ‡ฐ๐Ÿ‡ทKorean
๐Ÿ‡ฒ๐Ÿ‡ฝLatin American Spanish
๐Ÿ‡ฑ๐Ÿ‡ปLatvian
๐Ÿ‡ฑ๐Ÿ‡นLithuanian
๐Ÿ‡ฒ๐Ÿ‡พMalay
๐Ÿ‡ฎ๐Ÿ‡ณMalayalam
๐Ÿ‡ฎ๐Ÿ‡ณMarathi
๐Ÿ‡ณ๐Ÿ‡ดNorwegian
๐Ÿ‡ฎ๐Ÿ‡ทPersian
๐Ÿ‡ต๐Ÿ‡ฑPolish
๐Ÿ‡ต๐Ÿ‡นPortuguese
๐Ÿ‡ท๐Ÿ‡ดRomanian
๐Ÿ‡ท๐Ÿ‡บRussian
๐Ÿ‡ท๐Ÿ‡ธSerbian
๐Ÿ‡ธ๐Ÿ‡ฐSlovak
๐Ÿ‡ธ๐Ÿ‡ฎSlovenian
๐Ÿ‡ช๐Ÿ‡ธSpanish
๐Ÿ‡ฐ๐Ÿ‡ชSwahili
๐Ÿ‡ธ๐Ÿ‡ชSwedish
๐Ÿ‡ฎ๐Ÿ‡ณTamil
๐Ÿ‡ฎ๐Ÿ‡ณTelugu
๐Ÿ‡น๐Ÿ‡ญThai
๐Ÿ‡น๐Ÿ‡ทTurkish
๐Ÿ‡บ๐Ÿ‡ฆUkrainian
๐Ÿ‡บ๐Ÿ‡ธUS English
๐Ÿ‡ป๐Ÿ‡ณVietnamese

Extension Info & Metadata

Status
Active
Version
1.0.3
Size
0.23 MB
Rating
4.5/5
Reviews
4
Users
890
Type
Extension
Updated
Feb 27, 2025
Category
Workflow & planning
Price
Free
Featured
Yes
Visibility
Listed
Mature
No
By Google
No
Trusted
No

Publisher Contextual Analysis

Author
AI Webcam EffectsView Profile
Country
US
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
Yes
Mailbox exists
Yes
Address
1833 S OCEAN DR 1403 HALLANDALE BEACH, FL 33009 US
Website
Visit
Total Extensions
4
Active
3
Obsolete
1
Listed
4
Unlisted
0
Total Users
2,179
Screenshot 1

Screen recorder - simple, tiny, user-friendly and full-featured!

Free Screen recorder for Windows PC, Mac, Chromebook and Linux ๐Ÿ”ฅOur screen and audio recorder captures screen, webcamera, microphone and system sound, and autosaves recordings to your computer in MP4 format. โญ๏ธKey Features Capture screen in three modes: whole desktop, separate window or chrome tab Record screen with system sound, microphone, both of them or no audio at all. Our Screen recorder extension is free, without watermark, limits and sign ups! Looking for the best screen recorder for PC? Reasons to choose our Screen recorder: ๐ŸŽฌ Record unlimited videos โ€” all free, no sign ups! ๐Ÿš€ Recordings are automatically and instantly saved to your computer in MP4 format. ๐ŸŽฅ Record screen with audio from microphone and system sound. ๐Ÿ‘ Easy, compact and draggable interface โ€” it saves your screen space in full screen mode ๐Ÿ›ก๏ธ We respect your privacy โ€” you always know exactly what sources (video and audio) are being recorded, the extension does not collect or store any of your data. ๐Ÿ’ก How to make a screen recording? 1. Install the extension by clicking the "Add to Chrome" button 2. Open a new browser page or reload the current page 3. Click the extension icon 4. Grant access to your microphone if you want to record your voice 5. Select video and audio sources in the pop-up dialog 6. Record your video 7. Once you click Stop, the recording will be automatically downloaded to your Downloads directory โญ๏ธTop Use cases โ–ธ Record simple tutorial videos: how to use any website or application. โ–ธ Save time when discussing a problem or bug: create steps to reproduce a video that helps the developer understand the context and find the problem. โ–ธ Capture system sound: recording system sound works for Chrome tab option, so you can share your game play with all the details. โ–ธ Eliminate work meetings in favor of more effective, asynchronous communication.

Item
Type
Severity
Description
declarativeNetRequest
Permission
Critical
This permission allows the extension to define rules to block, redirect, or modify network requests. Rated Critical because it can control all network traffic, potentially blocking security updates or redirecting to malicious sites.
http://*/*
Host
Critical
Broad host access โ€” the extension can read/modify content on every website.
https://*/*
Host
Critical
Broad host access โ€” the extension can read/modify content on every website.

The extension uses declarativeNetRequest to forcibly blank the Content-Security-Policy header on every main frame and sub frame load across all websites. CSP is the primary browser defense against XSS and script injection; stripping it from every page visited removes that protection entirely, allowing injected scripts (including those the extension itself injects via content.js) to run without restriction on banking, email, and other sensitive sites.

rules.json (Line 1)
[  {    "id": 1,    "priority": 1,    "action": {      "type": "modifyHeaders",      "responseHeaders": [        {          "header": "content-security-policy",          "operation": "set",          "value": ""        }      ]    },    "condition": {      "resourceTypes": [        "main_frame",        "sub_frame"      ]    }  }]

The content script injects the full app.js bundle as a module script into the <head> of every HTML page matched by <all_urls>, running before any other scripts due to insertBefore(e, t.firstChild). Combined with the CSP-stripping rule in rules.json, this gives the injected script full DOM access and network reach on every site the user visits, without being subject to the host page's own security policy.

scripts/content.js (Line 146)
class T {  static injectScript() {    if (document.contentType === "text/html") try {      const e = document.createElement("script");      e.setAttribute("type", "module"), e.setAttribute("src", chrome.runtime.getURL("scripts/app.js")), e.async = !        1;      let t = document.head || document.getElementsByTagName("head")[0] || document.documentElement;      t.insertBefore(e, t.firstChild)    } catch (e) {      console.error("[ Content ]:", e)    }  }}T.injectScript();

The extension fetches a JavaScript worker script from `https://unpkg.com/webm-wasm@latest/dist/webm-worker.js` at runtime and executes it as a Web Worker, then also passes a WASM binary URL from the same CDN. The `@latest` version tag is unpinned, meaning the fetched code can change at any point without an extension update โ€” a compromise of the npm package or the unpkg CDN would result in arbitrary attacker-controlled JavaScript executing inside the extension. This is a classic supply-chain remote code loading vector.

scripts/app.js (Line 7806)
g = !1, fetch("https://unpkg.com/webm-wasm@latest/dist/webm-worker.js")  .then(function(U) {    U.arrayBuffer()      .then(function(c) {        T(H, c)      })  });...D = new Worker(a.workerPath), D  .postMessage(a.webAssemblyPath || "https://unpkg.com/webm-wasm@latest/dist/webm-wasm.wasm"), D  .addEventListener("message", function(U) {      U.data === "READY" ? (D.postMessage({            width: a.width,            height: a.height,            bitrate: a.bitrate || 1200,            timebaseDen: a.frameRate || 30,            realtime: a.realtime          })

The manifest exposes every extension resource (wildcard `*`) to every origin (`<all_urls>`). This means any web page can fetch or iframe any file inside the extension package, including internal scripts and assets. Combined with the CSP-stripping rule and content script injection, a malicious or compromised third-party page could leverage these exposed resources as injection vectors or fingerprint the extension to target its attack surface.

manifest.json (Line 43)
{  "web_accessible_resources": [    {      "resources": [        "*"      ],      "matches": [        "<all_urls>"      ]    }  ]}

By severity

Critical2
High1
Medium1
Low0

Versions scanned

Showing 1 of 3 scanned versions with more than one unique finding. Counts are unique findings that include each version.

Extension VersionCode Review Findings
1.0.34

Files with findings

4 distinct paths โ€” top paths by unique finding count:

  • manifest.json1
  • rules.json1
  • scripts/app.js1
  • scripts/content.js1
S.No.
Category
Severity
File
Summary
Found in Version
1Code Injection
critical
scripts/content.js (line 146)The content script injects the full app.js bundle as a module script into the <head> of every HTML page matched by <all_urls>, running before any other scripts due to insertBefore(e, t.firstChild). Combined with the Cโ€ฆ
2Privilege Escalation
critical
rules.json (line 1)The extension uses declarativeNetRequest to forcibly blank the Content-Security-Policy header on every main frame and sub frame load across all websites. CSP is the primary browser defense against XSS and script injecโ€ฆ
3Remote Code Loading
high
scripts/app.js (line 7806)The extension fetches a JavaScript worker script from `https://unpkg.com/webm-wasm@latest/dist/webm-worker.js` at runtime and executes it as a Web Worker, then also passes a WASM binary URL from the same CDN. The `@laโ€ฆ
4Privilege Escalation
medium
manifest.json (line 43)The manifest exposes every extension resource (wildcard `*`) to every origin (`<all_urls>`). This means any web page can fetch or iframe any file inside the extension package, including internal scripts and assets. Coโ€ฆ
URLs
31
IPv4
0
IPv6
0

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

Gain full insight into all external connections.

Upgrade for full visibility.

clients2.google.com/service/update2/crxhttps://clients2.google.com/service/update2/crx
webcameffects.app-https://webcameffects.app/
*/*http://*/*
*/*https://*/*
accounts.google.com-https://accounts.google.com
vuejs.org/error-reference/https://vuejs.org/error-reference/#runtime-${r}`;for(;s;
www.w3.org/2000/svghttp://www.w3.org/2000/svg
www.w3.org/1998/Math/MathMLhttp://www.w3.org/1998/Math/MathML
www.w3.org/1999/xlinkhttp://www.w3.org/1999/xlink
github.com/muaz-khan/RecordRTC|RecordRTC%7Dhttps://github.com/muaz-khan/RecordRTC|RecordRTC}
Showing 1 to 10 of 40 rows
Rows per page:

Gain full insight into all external connections.

Upgrade for full visibility.

No IP addresses found
Showing 1 to 3 of 10 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files (scanned top 25 shared text files)

No comparable text files found between these versions.

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.