Is ColorPick Eyedropper safe?
ColorPick Eyedropper is medium risk. ColorPick Eyedropper's code sends the hex value you pick to vidsbee.com when sharing is enabled. Sharing defaults off; testing never completed the color-pick flow, so no live traffic was observed. The GET path per color remains in code.
Who publishes itSam Larison - no other listings under this identity, 2 shared hostnames
Sam Larison - no other listings under this identity, 2 shared hostnames
What this publisher told the store about itself, and the other listings that told it the same thing.
Shared hosts - 2 hostnames
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Color picks can be sent to vidsbee.com
ColorPick Eyedropper's code sends the hex value you pick to vidsbee.com when sharing is enabled.
Sharing defaults off; testing never completed the color-pick flow, so no live traffic was observed.
The GET path per color remains in code.
You select a color while the extension's color-sharing option is enabled.
The option is off by default, so this path depends on the user or stored settings enabling it.
The extension prepares the selected color value for a request to vidsbee.com.
The request is made only when the selected hex value differs from the last one processed.
| Field | Value | Why it matters | |
|---|---|---|---|
Selected color | 336699 (illustrative) | This is the color value you chose from the page. It describes that selection, not the page URL or your account. |
The color-pick message and service-worker request path
function picked(ev){
if(isLocked){
lasthex = hex;
isLocked=false;
emptyNode(n);
}else{
try{
copyColorIfEna();
chrome.runtime.sendMessage({setColor:true,hex:hex,rgb:rgb,hsv:hsv}, function(response){});
}catch(e){
console.log("Sorry - ColorPick experienced a problem during setColor and has been disabled - Reload the page in order to pick colors here.", msg_bg_unavail, e);
exitAndDetachWithMessage();
}
isLocked=true;
setDisplay();
nextTip();
}
updateTip(); // for tip1, needed (changes if locked or unlocked)
setTimeout(keepWmAway, 250); // the new watermark could have overlapped the main control... avoid this!
chrome.runtime.sendMessage({setPickState:true,isPicking:!isLocked}, function(r){});
mmf(ev);
}function processSetColor(request){
if(request.hex) curentHex=request.hex;
if( lastHex != curentHex ){
//optionally store color to database...
if(loadedOptions.shareClors){
fetch('https://vidsbee.com/ColorPick/Daily/vcolors.php?colorhex='+curentHex)
.then(function(response){
// huh? it works? I don't have any host permisison claimed
// to me this is an indciation of how easy it is to do nefarious things with manifest version 3
// nuff said... (unlesssomeone made a special exception for me, aww how sweet)
// I'm going to guess service_worker: it's not restricted. yikes.
// mv2 basiaclly forced you to use permissions.<all_urls> instead of a restricted set so that ohter features would work ( for example, content_scripts that needed <all_urls>)
// now mv3 you don't have to claim anything and you can fetch (and presumably execute) anything
// and that thing could fetch more stuff....
// so this just breeds culplable deniablitiy, etc
// the spyware for profit ethos of our times demands it?
// not a fan...
});
}
//store colors
// tbd, it may already have a hex prefix...
loadedOptions.syncColorHistory=(loadedOptions.syncColorHistory||'')+"#"+curentHex;
saveColorHistories();
//console.log(request, loadedOptions.syncColorHistory)
}
if( curentHex ){
chrome.tabs.sendMessage(tabid,{hexValueWasSelected:curentHex.toLowerCase()},function(response){});
}
lastLastHex=lastHex;lastHex=curentHex;
}The shipped default keeps color sharing off
pOptions["shareClors"]={def:false,ind:0};- vidsbee.com
Receives the selected color hex value through the ColorPick Daily vcolors.php endpoint when sharing is enabled.
What it can do
Permissions this extension asks for, as declared in version 0.0.3.3. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Act on the current tab, but only after you click the extension
activeTab
See the address and title of every tab you have open
tabs
Run its own code inside the pages you visit
scripting
Store data in your browser
storage
Write to your clipboard
clipboardWrite