CRX aminer
Extension icon

Catchpoint Script Recorder

Version 1.9.21 View in Chrome Web Store

Last scanned: 2 months ago | force re-scan

Extension Details

Rating: 2.2 ★ (17 ratings)
Users: 771

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension has very low trust indicators with only 771 users and a poor 2.2-star rating from 17 reviews. The lack of visible developer information and company details raises additional concerns about accountability and transparency. The extension appears to be a legitimate script recording tool for Catchpoint's performance monitoring service, but the trust signals are weak.

Concerns:

The extension requests an extremely broad set of dangerous permissions that create significant security risks. The debugger permission is particularly concerning as it allows manipulation of other extensions and applications. The combination of webRequest and webRequestBlocking permissions enables real-time interception and modification of all web traffic. Content script injection across all URLs means the extension can access sensitive data on any website you visit. The ability to access cookies, downloads, and browsing data creates multiple vectors for data theft. Many of these permissions appear excessive for a script recording tool's core functionality.

Recommendations:

Given the critical risk level, only install this extension if absolutely necessary for Catchpoint monitoring work. If required, run it in a completely separate Chrome profile isolated from personal browsing and sensitive accounts. Regularly audit what data the extension might be collecting and consider removing it when not actively needed. Monitor your network traffic and be cautious about entering sensitive information while the extension is active. Consider alternative script recording solutions with more limited permission sets if available.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Dangerous Permission Combination: webRequest + webRequestBlocking
This extension can intercept, modify, and block web requests in real-time. This combination could be used to modify sensitive web traffic or steal data.
HIGH
High-Risk Permission: <all_urls>
This extension has the <all_urls> permission. Can access all websites and their content. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: debugger
This extension has the debugger permission. Can debug and manipulate other extensions/apps. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: downloads
This extension has the downloads permission. Can download files and access download history. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequestBlocking
This extension has the webRequestBlocking permission. Can block and modify web requests in real-time. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Older Manifest Version
This extension uses Manifest Version 2, which has fewer security restrictions than Manifest V3. Consider using extensions that have upgraded to V3.