Is Katalon Recorder (Selenium tests generator) safe?
Katalon Recorder is medium risk. Katalon Recorder writes a random ID to storage.local, storage.sync (follows the Google account across profiles), and a cookie expiring in 9999, sent to katalon-persistent-domain.com. Two fresh installs matched the ID across storages.
Who publishes itrecorder-services - 1 other listing from the same operator, none carrying a finding
recorder-services - 1 other listing from the same operator, none carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
1 other listing published from this account, 1k+ users between them, none of them carrying a finding.
Shared hosts - 16 hostnames
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Katalon Recorder writes a tracking ID to three storage locations at once
Katalon Recorder writes a random ID to storage.local, storage.sync (follows the Google account across profiles), and a cookie expiring in 9999, sent to katalon-persistent-domain.com.
Two fresh installs matched the ID across storages.
You install Katalon Recorder and open the extension for the first time.
No prior anonymous ID exists in the browser yet.
The extension generates a random ID and writes it to three separate storage locations at once.
chrome.storage.local, chrome.storage.sync, and a cookie on katalon-persistent-domain.com are all set in a single batched call.
| Field | Value | Why it matters | |
|---|---|---|---|
Local extension storage | chrome.storage.local.anonymousId = "77afdb31-5a88-43c4-be1b-309dcf7f0e77" | Cleared only if the user removes the extension or explicitly clears its local storage. | |
Synced extension storage | chrome.storage.sync.anonymousId = "77afdb31-5a88-43c4-be1b-309dcf7f0e77" | Copies the same ID to every other Chrome profile signed into the same Google account, including other devices. | |
Browser cookie | katalon_persistent_value_anonymousid=%2277afdb31-5a88-43c4-be1b-309dcf7f0e77%22; domain=.katalon-persistent-domain.com; expires=Fri, 31 Dec 9999 | Set on katalon-persistent-domain.com with an expiration date of year 9999, so it never expires on its own. |
From two fresh installs, both show the same ID in storage.local and storage.sync, confirming the dual-write is real, not just in source.
chrome.storage.local and chrome.storage.sync, key "anonymousId"{
"run_1": {
"storage.sync.anonymousId": "77afdb31-5a88-43c4-be1b-309dcf7f0e77",
"storage.local.anonymousId": "77afdb31-5a88-43c4-be1b-309dcf7f0e77"
},
"run_2": {
"storage.sync.anonymousId": "1b2999b2-3d15-41ab-a9d8-6a2e4ac2f8ca",
"storage.local.anonymousId": "1b2999b2-3d15-41ab-a9d8-6a2e4ac2f8ca"
}
}- katalon-persistent-domain.com
Receives the never-expiring cookie carrying the anonymous ID, used to restore the ID if local/sync storage is cleared.
- backend.katalon.com
Segment-compatible analytics endpoint (api/segment-kr/tracking) that receives the anonymous ID as userId on tracked events, including on install.
Run in the extension's service-worker console (chrome://extensions -> Katalon Recorder -> service worker -> Inspect) to read back all three copies of the anonymous ID and confirm whether they match.
(async () => {
const local = await chrome.storage.local.get('anonymousId');
const sync = await chrome.storage.sync.get('anonymousId');
const cookies = await chrome.cookies.getAll({ domain: 'katalon-persistent-domain.com' });
const cookie = cookies.find(c => c.name.startsWith('katalon_persistent_value_'));
console.log('local.anonymousId:', local.anonymousId);
console.log('sync.anonymousId:', sync.anonymousId);
console.log('cookie value:', cookie ? decodeURIComponent(cookie.value) : '(not found)');
console.log('all three match:', local.anonymousId && sync.anonymousId && cookie &&
local.anonymousId === sync.anonymousId &&
JSON.parse(decodeURIComponent(cookie.value)) === local.anonymousId);
})();- 1Open chrome://extensions, enable Developer mode.
- 2Find Katalon Recorder, click 'service worker' to open its DevTools console.
- 3Paste the script and press Enter.
- 4Compare the three logged values.
What it can do
Permissions this extension asks for, as declared in version 7.1.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on every site you visit
http://*/ and 2 more
See the address and title of every tab you have open
tabs
Act on the current tab, but only after you click the extension
activeTab
Add items to the right-click menu
contextMenus
Start, monitor and manage your downloads
downloads
See every page you navigate to, as you navigate to it
webNavigation
Show you desktop notifications
notifications
Read and change cookies, including the ones that keep you signed in
cookies
Store data in your browser
storage
Store an unlimited amount of data in your browser
unlimitedStorage
Attach to pages with the browser's debugger, which can read and rewrite anything on them
debugger
Run its own code inside the pages you visit
scripting
Run hidden pages in the background
offscreen