CRX aminer
Extension icon

Sendspark Video and Screen Recorder

Version 2.2.10 View in Chrome Web Store

Last scanned: about 3 hours ago

Extension Details

Developer: sendspark.com
Rating: 4.9 ★ (775 ratings)
Users: 10,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors: The extension has a strong user base with 10,000 users and an excellent 4.9-star rating from 775 reviews, indicating positive user experiences. The developer sendspark.com appears to be a legitimate video recording service. However, these positive indicators are overshadowed by significant security concerns.
Concerns: The extension's permission set is extremely broad and concerning for a video recording tool. The combination of cookies, tabs, and universal host permissions (*://*/*) creates a dangerous attack surface. The ability to inject content scripts into any website, including sensitive platforms like Gmail, LinkedIn, Salesforce, and HubSpot, poses significant privacy risks. The unsafe WebAssembly execution policy could hide malicious code. While video recording legitimately requires desktopCapture and tabCapture permissions, the extensive web access permissions seem excessive for core functionality.

The extension can potentially access login credentials, personal data, and business communications across all websites you visit. The broad content script injection capability means it could modify or steal data from any site.

Recommendations: Given the critical risk level, run this extension in a completely separate Chrome profile dedicated only to video recording activities. Never use this profile for sensitive activities like banking, email, or accessing confidential business systems. Consider alternative screen recording tools with more limited permissions. If you must use this extension, regularly audit what data it might be accessing and consider the business necessity versus privacy trade-offs.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
Unsafe WebAssembly Execution
This extension's Content Security Policy allows 'wasm-unsafe-eval', which permits potentially dangerous WebAssembly code execution. This could be used to hide malicious code or perform CPU-intensive operations.
MEDIUM
Access to Sensitive Domains
This extension requests access to sensitive domains: https://mail.google.com/. Ensure you trust this extension with access to these sites.
MEDIUM
Medium-Risk Permission: notifications
This extension has the notifications permission. Can show notifications.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.