Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeFireShot: Web Page Screenshots
Findings · 3
+4 more findings locked
HIGH FINDINGS · 3
  1. 01On `Send to Gmail` user action the SW injects a third-party SDK (InboxSDK / Streak `inboxsdk.js`) into the user's Gmail tab via `chrome.scripting.executeScript`, which then loads `https://www.inboxsdk.com/build/platform-implementation.js` over the network and reports errors to `https://www.inboxsdk.com/api/v2/errors`.
  2. 02Crash-report POST to a third-party domain (`screenshot-program.com`) carrying install GUID, full JS stack trace, user-typed comment and user-typed contact email.
  3. 03Extension reports JavaScript exceptions and native-host packet payloads to a vendor-controlled Sentry endpoint, including raw native-message bodies (truncated to 1024 bytes) which can contain captured-page metadata and filenames.
+4 more findings locked
OTHER EXTENSIONS

Is FireShot: Web Page Screenshots safe?

High risk

No summary available.

Evgeny Suslikovv2.1.3Chrome Web Store
75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+4 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026com.getfireshot.fireshot.extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact