Is Zight Screen Recorder, Screenshot App safe?
Zight accepts login tokens from any local file without verifying the sender and sends your account email to a third-party analytics service.
An external message handler stores any login_token and refresh_token it receives as the active Zight session, and because the extension allows messages from file://* as well as its own domains, a local HTML file you open could overwrite your credentials and redirect your captures to another account. On each screenshot or recording, the extension also transmits your account email, numeric user ID and organization ID to Segment analytics. A content-frame message listener additionally responds to 'reinject' messages from other pages without validating their origin.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.