πŸ“¦

Colorzilla

πŸ” Security Report Available
πŸ‘₯ 4M+ users
πŸ“¦ v4.1
πŸ’Ύ 410KiB
πŸ“… 2024-05-22
View on Chrome Web Store

Chrome will indicate if you already have this installed.

Overview

Advanced Eyedropper, Color Picker, Gradient Generator and other colorful goodies

Tags

Productivity/developer design productivity/developer

Privacy Practices

βœ“ Does not collect your data
βœ“ Does not sell your data to third parties
βœ“ Does not use data for unrelated purposes

Security Analysis

Analyzed v4.1 Β· Feb 22, 2026 Β· 15 JS files Β· 406 KB scanned

Permissions

tabs scripting storage offscreen <all_urls>

Code Patterns Detected

Function constructor used β€” dynamic code execution innerHTML assignment β€” potential XSS vector Makes HTTP requests Listens to keyboard events

External Connections

www.colorzilla.com colorzilla.com www.digitalmagicpro.com johndyer.name github.com people.mozilla.org en.wikipedia.org docs.python.org developer.mozilla.org wiki.ecmascript.org

Package Contents 87 files Β· 1.1MB

β–ΎπŸ“_locales398KB
β–ΎπŸ“cs17KB
{}messages.json17KB
β–ΎπŸ“de17KB
{}messages.json17KB
β–ΎπŸ“el20KB
{}messages.json20KB
β–ΎπŸ“en16KB
{}messages.json16KB
β–ΎπŸ“en_GB17KB
{}messages.json17KB
β–ΎπŸ“es17KB
{}messages.json17KB
β–ΎπŸ“es_41917KB
{}messages.json17KB
β–ΎπŸ“fr17KB
{}messages.json17KB
β–ΎπŸ“id17KB
{}messages.json17KB
β–ΎπŸ“it17KB
{}messages.json17KB
β–ΎπŸ“ja18KB
{}messages.json18KB
β–ΎπŸ“ko17KB
{}messages.json17KB
β–ΎπŸ“nl17KB
{}messages.json17KB
β–ΎπŸ“pl17KB
{}messages.json17KB
β–ΎπŸ“pt_BR17KB
{}messages.json17KB
β–ΎπŸ“pt_PT17KB
{}messages.json17KB
β–ΎπŸ“ru19KB
{}messages.json19KB
β–ΎπŸ“th20KB
{}messages.json20KB
β–ΎπŸ“tr17KB
{}messages.json17KB
β–ΎπŸ“uk19KB
{}messages.json19KB
β–ΎπŸ“vi17KB
{}messages.json17KB
β–ΎπŸ“zh_CN16KB
{}messages.json16KB
β–ΎπŸ“zh_TW17KB
{}messages.json17KB
β–ΎπŸ“_metadata12KB
{}verified_contents.json12KB
β–ΎπŸ“css8KB
🎨page.css2KB
🎨popup.css7KB
β–ΎπŸ“html15KB
🌐about.html2KB
🌐offscreen.html437B
🌐options.html5KB
🌐popup.html8KB
β–ΎπŸ“images50KB
β–ΎπŸ“material16KB
πŸ–Όart_palette.svg981B
πŸ–Όcolor.svg3KB
πŸ–Όcopy.svg742B
πŸ–Όdropper.svg847B
πŸ–Όexamine.svg1KB
πŸ–Όeyedropper-circle.svg428B
πŸ–Όgear-black.svg1KB
πŸ–Όgear.svg2KB
πŸ–Όgradient_linear.svg2KB
πŸ–Όhelp.svg1KB
πŸ–Όhistory.svg1KB
πŸ–Όspeech_ballon.svg710B
πŸ–Όupdate.svg645B
πŸ–Όwarning.svg675B
πŸ–Όcheckmark-icon.svg496B
πŸ–Όclose-button.png288B
πŸ–Όcollapse-button.png225B
πŸ–Όdrop-down-icon.png216B
πŸ–Όicon-128.png17KB
πŸ–Όicon-16.png851B
πŸ–Όicon-48.png4KB
πŸ–Όlogo-v2-640.svg9KB
πŸ–Όmain-icon-19-dark.png544B
πŸ–Όmain-icon-19.png535B
πŸ–Όselection-marker.gif1KB
β–ΎπŸ“js386KB
πŸ“œabout.js1KB
πŸ“œbackground-combo.js27KB
πŸ“œbrowser-utils.js2KB
πŸ“œcolor-history.js1KB
πŸ“œcontent-script-combo.js158KBlarge
πŸ“œglobal-shortcut.js606B
πŸ“œnew-feature-badge.js986B
πŸ“œoffscreen.js949B
πŸ“œoptions.js5KB
{}palette-db.json160KB
πŸ“œpopup.js21KB
πŸ“œutils.js7KB
β–ΎπŸ“lib265KB
β–ΎπŸ“jPicker122KB
β–ΎπŸ“css4KB
🎨jPicker-1.1.6.min.css4KB
β–ΎπŸ“images80KB
πŸ–ΌAlphaBar.png2KB
πŸ–ΌBars.png382B
πŸ–ΌMaps.png76KB
πŸ–ΌNoColor.png552B
πŸ–Όbar-opacity.png134B
πŸ–Όmap-opacity.png139B
πŸ–Όmappoint.gif93B
πŸ–Όpicker.gif146B
πŸ–Όpreview-opacity.png135B
πŸ–Όrangearrows.gif76B
🎨jPicker.css848B
πŸ“œjpicker-1.1.6.min.js37KB
πŸ“œchrome-promise.js4KB
πŸ“œjquery.js88KBlarge
πŸ“œunderscore.js52KBlarge
🌐EULA.html4KB
{}manifest.json984B
{}manifest.v2.json786B
{}manifest.v3.json918B

What This Extension Does

The ColorZilla extension appears to be a productivity tool for developers, offering advanced eyedropper, color picker, gradient generator, and other features.

Permissions Explained

  • tabs: Allows the extension to interact with web pages, which is standard for extensions that need to perform actions on specific websites.
  • scripting: Enables the extension to execute scripts in the context of web pages, also common for extensions that need to manipulate page content or behavior.
  • storage: Grants permission for the extension to store data locally, which is typical for extensions that need to remember user settings or cache data.
  • offscreen: This permission is unusual and not clearly explained by the extension's description. It could be related to rendering off-screen elements or handling background tasks but requires further investigation.
  • <all_urls>: Grants access to all URLs, which is a broad permission that allows the extension to interact with any web page, including those outside its intended functionality. This is unusual for an extension described as productivity/developer-focused.

What We Found in the Code

  • The use of function constructors for dynamic code execution is flagged as high-risk. However, without more context, it's difficult to determine if this is a legitimate coding pattern or a potential security issue.
  • innerHTML assignment is flagged as a medium-risk potential XSS vector. This could be a normal practice for UI rendering in certain contexts but warrants further investigation.
  • The extension makes HTTP requests, which is a common and expected behavior for extensions that need to fetch data from external sources.
  • Keyboard listeners are used, which could be for shortcuts or other legitimate purposes within the extension's UI.

External Connections

The extension communicates with several domains:
  • www.colorzilla.com, colorzilla.com: Expected for an extension that likely needs to communicate with its own website for updates, settings, or data.
  • www.digitalmagicpro.com: Unusual and not clearly related to the extension's functionality. Further investigation is needed to understand this connection.
  • johndyer.name, github.com, people.mozilla.org, en.wikipedia.org, docs.python.org, developer.mozilla.org, wiki.ecmascript.org: These domains appear to be external resources used for documentation, tutorials, or other non-security-related purposes.

Things to Consider

Given the extension's description and permissions, it seems that some of its declared permissions might be broader than necessary. The use of <all_urls> stands out as particularly concerning, given the extension's focus on developer productivity tools. Users may want to consider whether this level of access is justified for an extension described as "colorful goodies."
πŸ“¦
Capture a screenshot of your current page in entirety and reliablyβ€”without requesting any extra permissions!
Productivity/developer
λΈŒλΌμš°μ €μ—μ„œ λΌμ˜¨μ‹œνμ–΄μ˜ PCλ³΄μ•ˆ κΈ°λŠ₯을 μ‚¬μš©ν•˜κΈ° μœ„ν•œ ν™•μž₯ ν”„λ‘œκ·Έλž¨μž…λ‹ˆλ‹€.
Productivity/developer
πŸ“¦
Adds React debugging tools to the Chrome Developer Tools. Created from revision 3cde211b0c on 10/20/2025.
Productivity/developer
πŸ“¦
Identify web technologies
Productivity/developer