CRX aminer
Extension icon

Dadan - Screen Recording & Annotation Tool

Version 5.0.8 View in Chrome Web Store

Last scanned: about 8 hours ago

Extension Details

Developer: dadan.io
Rating: 4.7 ★ (52 ratings)
Users: 4,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors: The extension has a decent rating of 4.7 stars from 52 reviews and serves a legitimate purpose as a screen recording and annotation tool. However, the relatively small user base of 4,000 users and limited developer information raise some concerns about the extension's maturity and transparency.
Concerns: The extension's permission set is extremely broad and concerning for its stated purpose. While screen recording tools do need some elevated permissions, this extension requests access to cookies, all websites, download capabilities, and tab manipulation - far beyond what's necessary for basic screen recording. The ability to inject content scripts into all URLs means it can read and modify any webpage you visit. The unsafe WebAssembly execution policy is particularly troubling as it could hide malicious code. The combination of broad host permissions with cookie access creates significant privacy and security risks, as the extension could potentially track your browsing habits and steal sensitive information across all websites.
Recommendations: Given the critical risk level, avoid installing this extension on your main browser profile. If you must use it, create a dedicated Chrome profile with minimal sensitive data and only use it when actively recording screens. Consider alternative screen recording tools with more limited permissions, such as built-in browser recording features or desktop applications that don't require such extensive web access.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: downloads
This extension has the downloads permission. Can download files and access download history. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
Unsafe WebAssembly Execution
This extension's Content Security Policy allows 'wasm-unsafe-eval', which permits potentially dangerous WebAssembly code execution. This could be used to hide malicious code or perform CPU-intensive operations.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.