Is NCapture safe?

Medium risk

NCapture sends a persistent per-installation UUID to its vendor server on every OAuth credential request and uses a hardcoded AES key to decrypt those credentials client-side.

Each time a user captures content from Twitter, LinkedIn, Facebook, YouTube, or a web page, the extension contacts ncaptureservice.qsrinternational.com to fetch OAuth tokens. The request includes a unique client ID generated on first install and stored locally, allowing the vendor to track capture activity per installation. OAuth credentials returned by the server are encrypted with a fixed password and salt baked into the extension source, meaning anyone who can extract the extension code can derive the same decryption key.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

QSR Internationalv1.1.315.0Chrome Web Store
45Risk
Who publishes it

Lumivero Pty Ltd - no other listings under this identity, 3 shared hostnames

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
QSR International
Declared legal entity
Lumivero Pty Ltd
Registered address
1331 17th St suite 404, Denver, CO 80202-1566, US
Registered contact
Lumivero Pty Ltd

Shared hosts - 3 hostnames

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

esquire.com
Also called by 3 other listings, including BeeLine Reader
roughtype.com
Also called by 3 other listings, including BeeLine Reader
getsatisfaction.com
Also called by 6 other listings, including ActiveInbox: Organize Gmail™ tasks, OneLogin, OneLogin Extension

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 1.1.315.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every secure site you visit

    https://*/*

  • See the address and title of every tab you have open

    tabs

  • Show you desktop notifications

    notifications

  • Store data in your browser

    storage

  • Run its own code inside the pages you visit

    scripting

  • Run hidden pages in the background

    offscreen

  • Start, monitor and manage your downloads

    downloads

Where it sends data

Destinations our analysis observed NCapture contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • ncaptureservice.qsrinternational.com

    NCapture sends data to ncaptureservice.qsrinternational.com. No other extension we have analysed sends data here.

Updated 30 September 2026lgomjifbpjfhpodjhihemafahhmegbek