Is Handy Screenshot - Full Page Screen Capture safe?

Medium risk

Handy Screenshot replies to any page's postMessage request with a live Google Drive OAuth token, without checking the sender's origin.

When a user picks a Google Drive save folder, the extension opens a picker popup under a fixed, guessable window name and later answers a postMessage request for the OAuth token without verifying which page sent it, so a page that occupies that window name can request and receive the live drive.file access token. Separately, the extension's screenshot-capture overlay listens for page-level postMessage commands without an origin check, letting any script on the page it's running on trigger a full-page or selection capture and choose what happens to the resulting image.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

tainingv1.8.23Chrome Web Store
45Risk
Who publishes it

taining - no other listings under this identity, 3 shared hostnames

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
taining

Shared hosts - 3 hostnames

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

ohhandy.com
Also called by 1 other listing: Handy Screenshot
qrat.app
Also called by 2 other listings, including Handy Screenshot
rightonpage.dev
Also called by 2 other listings, including Handy Screenshot

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Updated 30 September 2026dajlhodahakobmgdiglkajjgbchiiccf