Starting analysis...
Version 1.9.21 View in Chrome Web Store
The extension has very low trust indicators with only 771 users and a poor 2.2-star rating from 17 reviews. The lack of visible developer information and company details raises additional concerns about accountability and transparency. The extension appears to be a legitimate script recording tool for Catchpoint's performance monitoring service, but the trust signals are weak.
The extension requests an extremely broad set of dangerous permissions that create significant security risks. The debugger permission is particularly concerning as it allows manipulation of other extensions and applications. The combination of webRequest and webRequestBlocking permissions enables real-time interception and modification of all web traffic. Content script injection across all URLs means the extension can access sensitive data on any website you visit. The ability to access cookies, downloads, and browsing data creates multiple vectors for data theft. Many of these permissions appear excessive for a script recording tool's core functionality.
Given the critical risk level, only install this extension if absolutely necessary for Catchpoint monitoring work. If required, run it in a completely separate Chrome profile isolated from personal browsing and sensitive accounts. Regularly audit what data the extension might be collecting and consider removing it when not actively needed. Monitor your network traffic and be cautious about entering sensitive information while the extension is active. Consider alternative script recording solutions with more limited permission sets if available.
| https://ssl.google-analytics.com | https://clients2.google.com/service/update2/crx | |
| https://github.com/KeesCBakker/StronlyTypedEvents/ | http://keestalkstech.com | |
| http://www.w3.org/TR/REC-CSS2/selector.html | http://www.w3.org/TR/2001/CR-css3-selectors-20011113/ | |
| http://svn.openqa.org/fisheye/browse/~raw | http://jira.openqa.org/browse/SEL-243 | |
| http://www.screengrab.org | http://snapsie.sourceforge.net/ | |
| http://jqueryui.com | http://jqueryui.com/themeroller/?bgShadowXPos=&bgOverlayXPos=&bgErrorXPos=&bgHighlightXPos=&bgContentXPos=&bgHeaderXPos=&bgActiveXPos=&bgHoverXPos=&bgDefaultXPos=&bgShadowYPos=&bgOverlayYPos=&bgErrorYPos=&bgHighlightYPos=&bgContentYPos=&bgHeaderYPos=&bgActiveYPos=&bgHoverYPos=&bgDefaultYPos=&bgShadowRepeat=&bgOverlayRepeat=&bgErrorRepeat=&bgHighlightRepeat=&bgContentRepeat=&bgHeaderRepeat=&bgActiveRepeat=&bgHoverRepeat=&bgDefaultRepeat=&iconsHover=url | |
| http://ace.ajax.org/ | https://github.com/Diullei | |
| https://github.com/DefinitelyTyped/DefinitelyTyped | https://github.com/ajaxorg/ace/wiki/Creating-or-Extending-an-Edit-Mode#wiki-extendingTheHighlighter | |
| https://github.com/claviska/jquery-dropdown | http://opensource.org/licenses/MIT | |
| http://www.w3.org/1999/xhtml | http://jshint.com/doc/options/#nonbsp | |
| http://simplemodal.com/ | http://ericmmartin.com | |
| http://www.apache.org/licenses/LICENSE-2.0 | http://groups.google.com/group/comp.lang.javascript/browse_thread/thread/a59ce20639c74ba1/a9d9f53e88e5ebb5 | |
| http://simonwillison.net/2006/Jan/20/escape/ | http://jquery.com/ | |
| http://jquery.org/license | http://sizzlejs.com/ | |
| http://json.org/json2.js | http://webreflection.blogspot.com/2007/08/global-scope-evaluation-and-dom.html | |
| http://docs.jquery.com/Utilities/jQuery.browser | http://javascript.nwbox.com/IEContentLoaded/ | |
| http://thinkweb2.com/projects/prototype/detecting-event-support-without-browser-sniffing/ | http://blindsignals.com/index.php/2009/07/jquery-delay/ | |
| http://fluidproject.org/blog/2008/01/09/getting-setting-and-removing-tabindex-values-with-javascript/ | http://www.w3.org/TR/2003/WD-DOM-Level-3-Events-20030331/ecma-script-binding.html | |
| http://isaacschlueter.com/2006/10/msie-memory-leaks/ | http://erik.eae.net/archives/2007/07/27/18.54.15/#comment-102291 | |
| http://pages.catchpoint.com/freetrial.html | https://www.catchpoint.com/script-recorder | |
| http://127.0.0.1:50121/browserresponse/?m=18&i= | http://127.0.0.1:50120/monitorservice/web/query? | |
| http://www.ecma-international.org/ecma-262/5.1/#sec-C | http://www.w3.org/2000/svg | |
| http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd | http://selenium-ide.openqa.org/profiles/test-case | |
| https://github.com/ | https://qaportal.catchpoint.com/ui | |
| https://portal.catchpoint.com/ui | http://www.catchpoint.com/ | |
| http://testng.org/testng-1.0.dtd | http://www.google.com/chrome/intl/en/webmasters-faq.html#useragent | |
| https://cs.chromium.org/chromium/src/v8/include/v8.h?type=cs&l=2502 | https://developer.mozilla.org/en-US/docs/Web/API/PerformanceResourceTiming | |
| https://chromedevtools.github.io/devtools-protocol/tot/Network/#method-emulateNetworkConditions | http://msdn.microsoft.com/en-us/library/8kb3ddd4 | |
| https://github.com/barbushin/javascript-errors-notifier/blob/master/content.js | https://developer.mozilla.org/en-US/docs/Web/API/EventTarget/dispatchEvent | |
| https://w3c.github.io/webdriver/webdriver-spec.html#pointer-actions | http://www.amazon.in/ | |
| http://sqa.3genlabs.net |
{ "key": "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAkgKzhoKrI6sjgB6eYSYlkFkzXPrEjbOm//KQ6MgqlZmSpjMD9teDOpTcaaRNBvScCO6pl/Wv/WL23jXI2CJW4RzWk3iJ7rWLVElTTB7M5nKfyDq1AuN64AfpAZmcH+tDEwjBN7Q9fzldLzurPuStiJ6ZGmLHILm2yajgGTYWqNs5zbcAiDyT0OPgtG7ZM2qP9ERBjH+S0GnOVn3n62eiVxX05uWJge8VJO1AXiSGU9pqQNZMrBq21wwszrjVxPL0+DxmH4zbF/fMjnBIscYBc/L4cXuQiyA+gpmOg88AIvqFmbYlClXOn5te0RZzBVAQul6pZYklxLShKdu16nDAFwIDAQAB", "name": "Catchpoint Script Recorder", "icons": { "16": "images/favicon.png", "48": "images/icon48.png", "128": "images/icon128.png" }, "version": "1.9.21", "background": { "page": "views/background.html" }, "short_name": "CP Recorder", "update_url": "https://clients2.google.com/service/update2/crx", "description": "Easily generate Selenium-based scripts for browser automation and testing.", "permissions": [ "background", "tabs", "browsingData", "contextMenus", "cookies", "debugger", "tabs", "downloads", "downloads.shelf", "webNavigation", "webRequest", "webRequestBlocking", "<all_urls>", "storage" ], "browser_action": { "default_icon": "images/favicon.png", "default_popup": "views/popup.html", "default_title": "Catchpoint Script Recorder" }, "content_scripts": [ { "js": [ "Chrome/selenium_atoms_compiled.js", "Chrome/catchpoint_common_string.js", "libraries/jquery-3.4.1.min.js", "Chrome/catchpoint_content_performance.js", "Chrome/catchpoint_content.js", "common/recorder_common.js", "common/catchpoint_recorder_constants.js", "content/catchpoint_recorder_content.js", "scripts/util.js", "scripts/instantTest.js" ], "run_at": "document_start", "matches": [ "<all_urls>" ], "all_frames": true } ], "manifest_version": 2, "externally_connectable": { "matches": [ "*://*.catchpoint.com/*" ] }, "minimum_chrome_version": "31.0", "content_security_policy": "script-src 'self' https://ssl.google-analytics.com; object-src 'self'", "web_accessible_resources": [ "views/blank.html" ] }
ⓘ CRXaminer has partnered with our friends at Secure Annex to provide additional findings unique to their platform.
Secure Annex also analyzes extensions from other browsers, IDEs, and can continuously monitor.
This extension may not yet be analyzed by Secure Annex.