Is Screen & Webcam recorder - Flonnect safe?

Medium risk

Screen Recorder is medium risk. Flonnect's bot-insert control in Meet, Teams, or Zoom sends the meeting URL to Flonnect's backend with credentials included. DA confirmed the Meet bot control is injected; live join needs an active-meeting click, so no body was captured.

Flonnectv8.2.89Chrome Web Store
45Risk
Who publishes it

Flonnect - 1 other listing from the same operator, none carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Flonnect

Same store account

1 other listing published from this account, 4k+ users between them, none of them carrying a finding.

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Meeting URL sent to Flonnect for recording bot

Flonnect's bot-insert control in Meet, Teams, or Zoom sends the meeting URL to Flonnect's backend with credentials included.

DA confirmed the Meet bot control is injected; live join needs an active-meeting click, so no body was captured.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You click Flonnect's control to add a notetaker bot to a Google Meet, Microsoft Teams, or Zoom meeting.

The extension did this

The extension sends the meeting URL to Flonnect's backend so the notetaker can join the call.

The background script includes browser credentials on the backend requests.

02EvidenceFIELD TABLE
Fields assembled for the bot-join flow
FieldValueWhy it matters
Meeting URL
https://meet.google.com/abc-defg-hij (illustrative)Identifies the exact call that the Flonnect notetaker is asked to join.
Notetaker name
Flonnect NotetakerControls the participant name shown for the bot when it joins the meeting.
Signed-in Flonnect session
credentials: includeLinks the bot-join request to the browser session that is signed in to Flonnect.
Meeting platform
zoomTells Flonnect whether the request came from Google Meet, Microsoft Teams, or Zoom status handling.
03EvidenceNETWORK CAPTURE
Captured request
POSThttps://backend.flonnect.com/flonnect/api/googlemeet/join-with-url
No live response body was captured; dynamic analysis confirmed the Google Meet control injection, while the live join POST requires an authenticated active meeting click.
04EvidenceTEMPORAL PATTERN
When this fires
Every 2 seconds

After the join request succeeds, the extension checks the bot's meeting status every two seconds until the call ends.

05EvidenceCODE COMPARE
The code that does this

The click handlers pass meeting URLs to the background script

What it actually does
Google Meet sends the current page URLcontent.js:109213-109218
const u = (0, e.useCallback)(() => {
  o("loading"), window.chrome.runtime.sendMessage({
    message: "insert_meet_bot",
    meetingUrl: window.location.href
  })
}, [o]);
Microsoft Teams sends the extracted meeting URLcontent.js:116590-116597
const u = (0, e.useRef)(null),
  d = (0, e.useCallback)(() => {
    o("loading"), window.chrome.runtime.sendMessage({
      message: "insert_meet_bot",
      meetingUrl: u.current,
      source: "outlook"
    })
  }, [o]);
Zoom sends the current page URL and sourcecontent.js:117083-117089
const d = (0, e.useCallback)(() => {
  o("loading"), window.chrome.runtime.sendMessage({
    message: "insert_meet_bot",
    meetingUrl: window.location.href,
    source: "zoom"
  })
}, [o]);
06EvidenceCODE COMPARE
The code that does this

The background handler sends the URL to Flonnect and polls status

What it actually does
Readable background handlerbackground.js:1168-1232
} else if (message.message === "insert_meet_bot") {
  try {
    const settingsRes = await fetch(`${host}/flonnect/api/googlemeet/settings`, {
      method: "GET",
      credentials: "include",
    });
    if (!settingsRes.ok) throw new Error("Failed to get bot settings");
    const settingsData = await settingsRes.json();
    const botName = settingsData?.notetakerName || "Flonnect Notetaker";

    const meetingUrl = message.meetingUrl;
    const joinRes = await fetch(`${host}/flonnect/api/googlemeet/join-with-url`, {
      method: "POST",
      credentials: "include",
      headers: { "Content-Type": "application/json" },
      body: JSON.stringify({ meetingUrl, notetakerName: botName }),
    });
    if (!joinRes.ok) throw new Error("Failed to join meeting");

    const joinData = await joinRes.json();
    const eventDbId = joinData?.eventDbId || joinData?.data?.eventDbId || joinData?.id;
    currentBotEventDbId = eventDbId;
    currentBotSource = message.source || "meet";

    chrome.tabs.sendMessage(senderId, {
      message: "insert_meet_bot_status",
      success: true,
      botName,
    });

    // Start polling bot status every 2 seconds
    if (botStatusPollInterval) {
      clearInterval(botStatusPollInterval);
      botStatusPollInterval = null;
    }
    botStatusPollTabId = senderId;

    const pollBotStatus = async () => {
      try {
        const res = await fetch(`${host}/flonnect/api/autorecord/get-bot-status`, {
          method: "POST",
          credentials: "include",
          headers: { "Content-Type": "application/json" },
          body: JSON.stringify({ eventDbId, source: currentBotSource }),
        });
        const data = await res.json();
        console.log(data,"data in sytatys")
        const status = data?.data?.botStatus;

        chrome.tabs.sendMessage(botStatusPollTabId, {
          message: "bot_status_update",
          status,
        }).catch(() => {});

        if (status === "bot.call_ended" || status === "bot.done") {
          clearInterval(botStatusPollInterval);
          botStatusPollInterval = null;
        }
      } catch (e) {
        console.error("Bot status poll error", e);
      }
    };

    pollBotStatus();
    botStatusPollInterval = setInterval(pollBotStatus, 2000);
  } catch (e) {
    chrome.tabs.sendMessage(senderId, {
      message: "insert_meet_bot_status",
      success: false,
    });
  }
}
07EvidenceTHIRD PARTY LIST
External host receiving the meeting-bot requests
  • backend.flonnect.com

    Receives the settings request, the meeting URL join request, and repeated bot-status polling for Flonnect's notetaker flow.

Updated 30 September 2026lkeokcighogdliiajgbbdjibidaaeang