Take Webpage Screenshots Entirely - FireShotSecurity Analysis

Chromev2.1.4.7MV3February 16, 2026 at 03:28 PM
8.4CRITICAL
8.4 CRITICAL

This extension shows critical risk indicators. It requests highly sensitive permissions combined with suspicious code patterns. Proceed with extreme caution.

Based on 8 permissions including high-risk ones, 365 code findings, 2 dangerous combinations.

Dangerous Combinations(2)

HIGHTab tracking + external communication

Extension tracks open tabs and communicates with external servers — potential browsing surveillance.

tabs+external network request
CRITICALNative messaging + dynamic code execution

Extension communicates with native apps and executes dynamic code — potential sandbox escape vector.

nativeMessaging+eval/Function/dynamic code
Permissions
8.5/10
Code
10.0/10
Combinations
10.0/10
Manifest/CSP
1.0/10

Permissions(8 analyzed)

Code Findings(29 patterns, 365 total)

Libraries(2 detected)

2 libraries detected, 2 with known vulnerabilities

Content Security Policy

CSP Present(1 issue)
LOW
object-srcobject-src not restricted

object-src is not set to 'none'. Plugins like Flash can be embedded, which may allow code execution.

Manifest Analysis(0 findings)

Resolved from __MSG_* i18n placeholders:

Name: Take Webpage Screenshots Entirely - FireShot

Description: Take FULL webpage screenshots. Capture, edit and save them to PDF/JPEG/GIF/PNG, upload, print, send to OneNote, clipboard or email.

No manifest-level concerns found.

External Domains(38)

aaddons.mozilla.orgapi.inboxsdk.comauth.getfireshot.combbit.lyblog.chromium.orgcli.vuejs.orgdocs.sentry.ioelement-plus.orgfb.mefeross.orggetbootstrap.comgetfireshot.comgithub.comgmail.comjedwatson.github.iomail.google.commyaccount.google.new-issue.vuejs.orgo4507590541901824.ingest.us.sentry.iopeople-pa.clients6.google.compluspubsub.googleapis.comreact.devreactjs.orgregister.inboxsdk.comscreenshot-program.comssl.getfireshot.comssl.gstatic.comsupport.mozilla.orgtinyurl.comu0442www.example.comwww.gstatic.comwww.inboxsdk.comxyoutu.be

Indicators of Compromise

66 indicators of compromise found

File Statistics

179
Total Files
29
JS Files
39.0 MB
Total Size

Other Scanned Extensions