Is ColorPick Eyedropper safe?

Medium risk

ColorPick Eyedropper is medium risk. ColorPick Eyedropper's code sends the hex value you pick to vidsbee.com when sharing is enabled. Sharing defaults off; testing never completed the color-pick flow, so no live traffic was observed. The GET path per color remains in code.

Sam Larisonv0.0.3.3Chrome Web Store
45Risk
Who publishes it

Sam Larison - no other listings under this identity, 2 shared hostnames

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Sam Larison

Shared hosts - 2 hostnames

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

urltocheck1.org
Also called by 1 other listing: Colorpick Eyedropper
vidsbee.com
Also called by 3 other listings, including Colorpick Eyedropper

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-200
SourceAI SANDBOX

Color picks can be sent to vidsbee.com

ColorPick Eyedropper's code sends the hex value you pick to vidsbee.com when sharing is enabled.

Sharing defaults off; testing never completed the color-pick flow, so no live traffic was observed.

The GET path per color remains in code.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You select a color while the extension's color-sharing option is enabled.

The option is off by default, so this path depends on the user or stored settings enabling it.

The extension did this

The extension prepares the selected color value for a request to vidsbee.com.

The request is made only when the selected hex value differs from the last one processed.

02EvidenceFIELD TABLE
Field placed in the vidsbee.com request
FieldValueWhy it matters
Selected color
336699 (illustrative)This is the color value you chose from the page. It describes that selection, not the page URL or your account.
03EvidenceNETWORK CAPTURE
Captured request
GEThttps://vidsbee.com/ColorPick/Daily/vcolors.php?colorhex=336699
04EvidenceCODE COMPARE
The code that does this

The color-pick message and service-worker request path

What it actually does
Content script sends the picked color to the extension workerdeobfuscated/colorpick.user.js
function picked(ev){
	if(isLocked){
		lasthex = hex;
		isLocked=false;
		emptyNode(n);
	}else{
		try{
			copyColorIfEna();
			chrome.runtime.sendMessage({setColor:true,hex:hex,rgb:rgb,hsv:hsv}, function(response){});
		}catch(e){
			console.log("Sorry - ColorPick experienced a problem during setColor and has been disabled - Reload the page in order to pick colors here.", msg_bg_unavail, e);
			exitAndDetachWithMessage();
		}
		isLocked=true;
		setDisplay();
        nextTip();
	}
	updateTip(); // for tip1, needed (changes if locked or unlocked)
    setTimeout(keepWmAway, 250); // the new watermark could have overlapped the main control... avoid this!
	chrome.runtime.sendMessage({setPickState:true,isPicking:!isLocked}, function(r){});
	mmf(ev);
}
Service worker sends the selected hex value when sharing is enableddeobfuscated/background.js
function processSetColor(request){
	if(request.hex) curentHex=request.hex;
	if( lastHex != curentHex ){
		//optionally store color to database...
		if(loadedOptions.shareClors){
			fetch('https://vidsbee.com/ColorPick/Daily/vcolors.php?colorhex='+curentHex)
			.then(function(response){
				// huh?  it works?  I don't have any host permisison claimed
				// to me this is an indciation of how easy it is to do nefarious things with manifest version 3
				// nuff said... (unlesssomeone made a special exception for me, aww how sweet)
				// I'm going to guess service_worker: it's not restricted.  yikes.
				// mv2 basiaclly forced you to use permissions.<all_urls> instead of a restricted set so that ohter features would work ( for example, content_scripts that needed <all_urls>)
				// now mv3 you don't have to claim anything and you can fetch (and presumably execute) anything
				// and that thing could fetch more stuff....
				// so this just breeds culplable deniablitiy, etc
				// the spyware for profit ethos of our times demands it?
				// not a fan...
			});
		}
		//store colors
		// tbd, it may already have a hex prefix...
		loadedOptions.syncColorHistory=(loadedOptions.syncColorHistory||'')+"#"+curentHex;
		saveColorHistories();
		
		
		//console.log(request, loadedOptions.syncColorHistory)
	}
	if( curentHex ){
		chrome.tabs.sendMessage(tabid,{hexValueWasSelected:curentHex.toLowerCase()},function(response){});
	}
	lastLastHex=lastHex;lastHex=curentHex;
}
05EvidenceCODE COMPARE
The code that does this

The shipped default keeps color sharing off

What it actually does
pOptions["shareClors"]={def:false,ind:0};
06EvidenceTHIRD PARTY LIST
External host named by the request path
  • vidsbee.com

    Receives the selected color hex value through the ColorPick Daily vcolors.php endpoint when sharing is enabled.

What it can do

Permissions this extension asks for, as declared in version 0.0.3.3. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Act on the current tab, but only after you click the extension

    activeTab

  • See the address and title of every tab you have open

    tabs

  • Run its own code inside the pages you visit

    scripting

  • Store data in your browser

    storage

  • Write to your clipboard

    clipboardWrite

Updated 30 September 2026ohcpnigalekghcmgcdcenkpelffpdolg