πŸ“¦

Vidyard - Screen Recorder & Screen Capture

✨ AI-Powered πŸ” Security Report Available
πŸ‘₯ 300K+ users
πŸ“¦ v4.2.3
πŸ’Ύ 42.58MiB
πŸ“… 2026-02-13
View on Chrome Web Store

Chrome will indicate if you already have this installed.

Lets you capture your screen, share your video and track who's watching it, making it a valuable asset for marketers, sales teams and customer support professionals looking to create engaging content and analyze its performance.

Overview

Record your screen or webcam, share your video, and track who's watching it! This screen recorder for Chrome is built to help you sell better. Easily record your webcam, screen, or both in just a few clicks. Share your video with a link and track when your videos get watched.
From prospecting to proposals, Vidyard’s screen recorder makes it easy to connect with more leads, qualify for better opportunities, and close more deals with personalized video.

KEY FEATURES

πŸ–₯ Record your screen directly from your browser
✨ Use AI to write personalized scripts at scale
πŸ”— Easily share your video link through email, social media, and more
πŸ’¬ Get notified whenever someone views your video
πŸ“š Manage all your Vidyard videos in one place, across devices and teams
πŸ€Ήβ€β™€οΈ Integrate Vidyard videos with the sales tools your team already uses

OVER 12 MILLION PEOPLE CHOOSE VIDYARD

From HubSpot, Microsoft, LinkedIn, Marketo, Salesforce, and more, Vidyard is the video creation tool built to help sales teams sell better.

Screen Recorder

- Record your screen to create HD sales videos
- Record videos wherever you are with Vidyard’s iOS, Android, and desktop apps
- Use AI to write speaker notes and deliver your message with confidence
- Access on-screen drawing tools to highlight important information and drive your message home

Edit Your Videos

Trim your videos to remove unwanted footage
Stitch multiple videos together into one, so you don’t have to master the perfect single take
Choose an animated thumbnail from your footage

Share Your Videos Everywhere

- Share a link to your video via email, social, or however you communicate for freeβ€”no downloads or attachments
- Embed videos for inline playback on your website, blog, landing pages, and more
- Easily share videos to Facebook, Twitter, and LinkedIn with just a couple of clicks

Measure Video Success

- Get notified whenever anyone watches your videos
- Track engagement to see who’s watching your videos and for how long
- Integrate Vidyard with your CRM to quantify video pipeline, revenue, and ROI

Vidyard is the Video Platform Built for Sales

From easy video creation to powerful video analytics; from small business to enterprise. Vidyard’s free screen recording platform has all the features your business needs to connect with your audience, drive engagement, and delight your customers, wherever they are.

About Vidyard

Vidyard is the leading video platform for salespeople. More than 250,000 companies use its video messaging and video hosting tools to engage their customers and prospects more effectively.

(Please note, this extension was previously named Vidyard GoVideo.)

Tags

Productivity/workflow screenshot video productivity/workflow

Privacy Practices

βœ“ Not being sold to third parties, outside of the approved use cases
βœ“ Not being used or transferred for purposes that are unrelated to the item's core functionality
βœ“ Not being used or transferred to determine creditworthiness or for lending purposes
v4.2.3 Critical Scanned Feb 22, 2026

Security Analysis

Analyzed v4.2.3 Β· Feb 22, 2026 Β· 21 JS files Β· 26058 KB scanned

Permissions

storage tabs webNavigation scripting notifications activeTab offscreen system.display alarms tabGroups downloads <all_urls>

Code Patterns Detected

innerHTML assignment β€” potential XSS vector Makes HTTP requests Listens to keyboard events

External Connections

www.w3.org api.vidyard.com secure.vidyard.com s3.amazonaws.com avatar.vidyard.com auth.vidyard.com github.com extension-backend.vidyard.com rollbar.com heapanalytics.com goodbye.vidyard.com sso.vidyard.com +8 more

Package Contents 195 files Β· 79.5MB

β–ΎπŸ“_metadata26KB
{}verified_contents.json26KB
β–ΎπŸ“images30.7MB
β–ΎπŸ“brands216KB
πŸ–Όinside_sales_excellence.svg187KB
πŸ–Όjb_sales.svg4KB
πŸ–Όkatherine_caldwell.svg5KB
πŸ–Όsales_feed.svg5KB
πŸ–Όsales_gravy.svg4KB
πŸ–Όsalesloft.svg4KB
πŸ–Όshari_levitin.svg2KB
πŸ–Όtodd_caponi.svg2KB
πŸ–Όvidyard.svg3KB
β–ΎπŸ“components5KB
πŸ“„BannerIcon.jsx2KB
πŸ“„TemplatesIcon.jsx4KB
β–ΎπŸ“icons171KB
πŸ–Όicon-ai-camera-active.svg899B
πŸ–Όicon-ai-camera-inactive.svg899B
πŸ–Όicon-ai-screen-camera-active.svg1KB
πŸ–Όicon-ai-screen-camera-inactive.svg1KB
πŸ–Όicon-animated-sparkles.gif71KB
πŸ–Όicon-camera-active.svg785B
πŸ–Όicon-camera-gmail.svg420B
πŸ–Όicon-camera-off-disabled.svg702B
πŸ–Όicon-camera-off.svg836B
πŸ–Όicon-camera-on-disabled.svg663B
πŸ–Όicon-camera-on.svg664B
πŸ–Όicon-camera-only-disabled.svg822B
πŸ–Όicon-camera-only-on.svg819B
πŸ–Όicon-camera.svg785B
πŸ–Όicon-caret-up.svg227B
πŸ–Όicon-check.svg296B
πŸ–Όicon-circle-white.svg266B
πŸ–Όicon-circle.svg270B
πŸ–Όicon-close.svg388B
πŸ–Όicon-hover-close.svg920B
πŸ–Όicon-hover-record-person.svg1KB
πŸ–Όicon-hover-record-screen.svg2KB
πŸ–Όicon-hover-video.svg881B
πŸ–Όicon-hover-vidyard-logo.svg8KB
πŸ–Όicon-mic-disabled.svg741B
πŸ–Όicon-mic-off.svg929B
πŸ–Όicon-mic-on.svg701B
πŸ–Όicon-notes.svg2KB
πŸ–Όicon-pause.svg321B
πŸ–Όicon-play.svg218B
πŸ–Όicon-screen-active.svg886B
πŸ–Όicon-screen-camera-active.svg1KB
πŸ–Όicon-screen-camera.svg1KB
πŸ–Όicon-screen-on.svg580B
πŸ–Όicon-screen.svg886B
πŸ–Όicon-square.svg264B
πŸ–Όicon-sticky.svg591B
πŸ–Όicon-tab-on.svg579B
πŸ–Όicon-upload-128-1.png4KB
πŸ–Όicon-upload-128-2.png5KB
πŸ–Όicon-upload-128-3.png5KB
πŸ–Όicon-upload-48-1.png2KB
πŸ–Όicon-upload-48-2.png2KB
πŸ–Όicon-upload-48-3.png2KB
πŸ–Όicon-upload.svg2KB
πŸ–Όicon-vidyard-128.png9KB
πŸ–Όicon-vidyard-16.png2KB
πŸ–Όicon-vidyard-48.png4KB
πŸ–Όicon-vidyard-beta-128.png7KB
πŸ–Όicon-vidyard-beta-16.png1KB
πŸ–Όicon-vidyard-beta-48.png5KB
πŸ–Όicon-vidyard-dev-128.png4KB
πŸ–Όicon-vidyard-dev-16.png615B
πŸ–Όicon-vidyard-dev-48.png2KB
πŸ–Όicon-vidyard-staging-128.png4KB
πŸ–Όicon-vidyard-staging-16.png618B
πŸ–Όicon-vidyard-staging-48.png2KB
β–ΎπŸ“mocks10.4MB
πŸ–Όai-avatar-mock-01.svg9.7MB
πŸ–Όai-avatar-mock-02.svg265KB
πŸ–Όai-avatar-mock-03.svg270KB
πŸ–Όai-avatar-mock-04.svg267KB
β–ΎπŸ“speakerNotesOnboarding16.5MB
πŸ–Όcongrats.svg492KB
πŸ–Όdesktop-1.svg1KB
πŸ–Όdesktop-2.svg2KB
πŸ–Όintro.svg26KB
πŸ–Όmultiple-monitors-screen-1.svg1.9MB
πŸ–Όmultiple-monitors-screen-2.svg7MB
πŸ“„share-tab.mp42.1MB
πŸ“„share-window.mp42MB
πŸ“„single-monitor-arrange.mp43MB
β–ΎπŸ“virtualBackgrounds1003KB
πŸ–Όcozy-cafe.jpg441KB
πŸ–Όoffice-desk.jpg253KB
πŸ–Όoffice-room.jpg308KB
πŸ“„BlurIcon.jsx2KB
πŸ–ΌGoogle.svg757B
πŸ–ΌLinkedIn.svg431B
πŸ–ΌOutlook.svg333B
πŸ–ΌVidyardLogoText.svg4KB
πŸ–Όai-avatars-generating-video.svg30KB
πŸ–Όarrow-1.svg849B
πŸ–Όarrow-2.svg396B
πŸ–Όavatar-placeholder.svg12KB
πŸ–Όchrome-library-empty-state.svg58KB
πŸ–Όconnection-established.svg38KB
πŸ–Όenable-permissions-vidyard.gif263KB
πŸ–Όfailed-to-load.svg43KB
πŸ–Όfavicon.ico15KB
πŸ–Όicon-vidyard-48.png4KB
πŸ–Όicon-vidyard-beta-48.png5KB
πŸ–Όicon-vidyard-dev-48.png2KB
πŸ–Όicon-vidyard-staging-48.png2KB
πŸ–Όkeyboard-hover.svg3KB
πŸ–Όkeyboard.svg3KB
πŸ–Όman-laptop-screen-recording.png14KB
πŸ–Όman-waving-video-recording.png71KB
πŸ–Όmessage.svg772B
πŸ–Όnew-update-hover.svg1KB
πŸ–Όnew-update.svg1KB
πŸ–Όnotifications-empty-state.svg13KB
πŸ–Όplayer-thumbnail.svg583B
πŸ–Όprompt-example.png34KB
πŸ–Όps_no-time.svg945B
πŸ–Όrecording-blocked.svg96KB
πŸ–Όrecording-page-background-bottom-left.svg380KB
πŸ–Όrecording-page-background-bottom-right.svg5KB
πŸ–Όrecording-page-background-top-right.svg25KB
πŸ–Όscreen-share-example.png34KB
πŸ–Όsquiggly-arrow.svg2KB
πŸ–Όthumbnail-placeholder.png16KB
πŸ–Όtry-ai-avatars.png181KB
πŸ–Όunblock-cam-vidyard.gif25KB
πŸ–Όunblock-mic-vidyard.gif25KB
πŸ–Όwoman-with-trophy-celebrating.png214KB
πŸ–Όworkspace-promotion.svg784KB
β–ΎπŸ“modular5.4MB
β–ΎπŸ“models243KB
πŸ“„selfiesegmentation_mlkit-256x256-2021_01_19-v1215.f16.tflite243KB
β–ΎπŸ“tensorflow-deps5.1MB
βš™tflite-simd.wasm2.9MB
βš™tflite.wasm2.2MB
β–ΎπŸ“worklets1KB
πŸ“œscribeAudioProcessor.js1KB
πŸ–Ό02d0dd3fda7de08cc94c.svg58KB
πŸ–Ό3333e1811343fc72830f.jpg253KB
πŸ–Ό5e1bff2aedb54e7436fb.jpg308KB
πŸ“œ639.min.js26KB
πŸ“œ816.min.js2.3MBlarge
πŸ“„816.min.js.LICENSE.txt10KB
πŸ–Ό9f609d1f398136f2dc9e.svg296B
πŸ–Όaa18e4928bd8e7fe12bb.jpg441KB
🌐authenticationSuccess.html160B
🌐camera.html272B
🎨camera.min.css312B
πŸ“œcamera.min.js519KBlarge
🌐cameraRecording.html415B
🎨cameraRecording.min.css2.6MB
πŸ“œcameraRecording.min.js694KBlarge
πŸ“„cameraRecording.min.js.LICENSE.txt2KB
πŸ“œckeCheckVidyardSupport.min.js335B
🎨ckeInsertThumbnailLink.min.css1B
πŸ“œckeInsertThumbnailLink.min.js90KBlarge
πŸ“„ckeInsertThumbnailLink.min.js.LICENSE.txt483B
🎨content.min.css99KB
πŸ“œcontent.min.js3.9MBlarge
πŸ“„content.min.js.LICENSE.txt2KB
πŸ–Όea10559d686140a9abd4.png181KB
🎨eloquaEngageContent.min.css557B
πŸ“œeloquaEngageContent.min.js579KBlarge
πŸ“„eloquaEngageContent.min.js.LICENSE.txt1KB
🌐extensionPopup.html363B
🎨gmailContent.min.css310B
πŸ“œgmailContent.min.js1.6MBlarge
πŸ“„gmailContent.min.js.LICENSE.txt3KB
🎨gongContent.min.css1B
πŸ“œgongContent.min.js392KBlarge
🎨hoverRecorder.min.css2KB
πŸ“œhoverRecorder.min.js392KBlarge
πŸ“œinboxSDKpageWorld.min.js169KBlarge
πŸ“„inboxSDKpageWorld.min.js.LICENSE.txt848B
🌐library.html253B
🎨library.min.css64B
πŸ“œlibrary.min.js432KBlarge
🎨linkedInContent.min.css4.4MB
πŸ“œlinkedInContent.min.js575KBlarge
πŸ“„linkedInContent.min.js.LICENSE.txt1KB
{}manifest.json3KB
🌐offscreen.html396B
🎨offscreen.min.css1B
πŸ“œoffscreen.min.js2.8MBlarge
πŸ“„offscreen.min.js.LICENSE.txt10KB
🌐overlayPopup.html277B
🎨overlayPopup.min.css2.6MB
πŸ“œoverlayPopup.min.js1.3MBlarge
πŸ“„overlayPopup.min.js.LICENSE.txt3KB
🎨popup.min.css4.5MB
πŸ“œpopup.min.js1.3MBlarge
πŸ“„popup.min.js.LICENSE.txt3KB
🎨salesforceContent.min.css557B
πŸ“œsalesforceContent.min.js575KBlarge
πŸ“„salesforceContent.min.js.LICENSE.txt1KB
🎨service-worker.min.css1B
πŸ“œservice-worker.min.js511KBlarge
πŸ“„service-worker.min.js.LICENSE.txt859B
🌐speakerNotes.html402B
🎨speakerNotes.min.css2.6MB
πŸ“œspeakerNotes.min.js7.5MBlarge
πŸ“„speakerNotes.min.js.LICENSE.txt2KB

What This Extension Does

This extension records your screen and webcam to create personalized sales videos, which can be shared and tracked for engagement.

Permissions

  • storageexpected: Lets the extension save settings or data locally on your computer. A user might care if they're concerned about privacy of their browsing habits or personal information stored by extensions.
  • tabsexpected: Allows the extension to view and interact with your open browser tabs. This is needed if it wants to record specific pages or inject scripts into them.
  • webNavigationexpected: Enables the extension to track when you navigate between web pages. Useful for logging video engagement but could also log sensitive navigation behavior.
  • scriptingexpected: Lets the extension inject JavaScript into web pages. This is necessary for screen recording functionality but could also allow unauthorized code execution.
  • notificationsexpected: Allows the extension to show pop-up messages in your browser. This is used for alerts like when someone views a video.
  • activeTabexpected: Gives the extension access to the currently active tab only when triggered by user action (like clicking a button). This is standard and generally safe.
  • offscreenexpected: Enables the extension to run background tasks even when no visible UI is present. Needed for recording screen or audio in the background.
  • system.displayexpected: Used to access display information such as resolution or monitor count. Necessary if the extension needs to record multiple screens.
  • alarmsexpected: Enables scheduling background tasks at specific intervals. May be used to periodically check video analytics or sync data.
  • tabGroupsexpected: Allows grouping and managing tabs together. This is likely used for organizing video-related tasks but doesn't pose a direct risk.
  • downloadsexpected: Permits the extension to download files directly from the internet into your browser's downloads folder.
  • <all_urls>check this: Gives the extension broad permission to interact with any website you visit. This is a major concern because it allows access to all web traffic, including private information. ⚠ 1

Your Data

The extension can access and send data to several external servers, including Vidyard’s own services and analytics providers. It may collect information about your browsing behavior or video interactions.

Code Findings

InnerHTML assignmentMedium

The code uses innerHTML to insert content into web pages. This can be risky if that inserted content comes from an untrusted source, as it might allow attackers to run malicious scripts.

πŸ’‘ Common practice in extensions that modify page content dynamically based on user actions or data fetched from APIs.

HTTP request generationInfo

The extension makes network requests to external servers. This is normal for an app that uploads videos and tracks analytics, but it's worth noting.

Keyboard event listenerHigh

The extension listens to keyboard events, which could be used to capture keystrokes or track user input β€” a potential privacy concern.

Trustworthiness

  • Developer: Developer name is not listed in the scan data; no clear indication of company or support links.
  • Privacy Policy: No privacy policy was found during scanning. This raises concerns about how user data may be handled, especially given the wide permissions and access to sensitive sites like Gmail and LinkedIn.
  • Install Base: Installed by 300,000 users. Recent updates suggest ongoing maintenance.
Bottom Line

This extension appears consistent with its purpose, but the <all_urls> permission means it can access all websites you visit and potentially collect sensitive data from any site β€” including private emails or business documents. Users should carefully consider whether they trust this level of access before installing.

Extension Overview

This extension records your screen and webcam to create personalized sales videos, which can be shared and tracked for engagement.

Permissions

  • storageexpected: Exposes Chrome's storage API allowing read/write access to extension-managed local storage (chrome.storage.local). An attacker could potentially extract saved credentials, session tokens, or usage patterns from this area. Not inherently risky unless misused for data exfiltration.
  • tabsexpected: Grants access to chrome.tabs API including tab content, URL information, and ability to manipulate tabs (e.g., close, activate). Could be used by an attacker to monitor browsing activity or inject malicious code into active tabs.
  • webNavigationexpected: Provides access to chrome.webNavigation API, which allows monitoring of page load events and URL changes across all tabs. Could be leveraged by an attacker to observe user activity or detect sensitive sites visited.
  • scriptingexpected: Grants access to chrome.scripting API, enabling injection of scripts into arbitrary tabs or frames. If misused, this can lead to full page compromise or data theft from targeted domains.
  • notificationsexpected: Exposes chrome.notifications API, which can display system-level notifications. While not directly harmful, could be abused for phishing or misleading UI prompts if combined with other permissions.
  • activeTabexpected: Provides limited access via chrome.tabs API restricted to current tab. Only usable after direct user interaction, so low risk unless combined with other permissions.
  • offscreenexpected: Allows creation of offscreen documents via chrome.offscreen API, useful for long-running processes like screen capture without needing a popup window.
  • system.displayexpected: Exposes chrome.system.display API, which provides details about connected displays and screen geometry. Could potentially be used for fingerprinting purposes.
  • alarmsexpected: Grants access to chrome.alarms API, allowing periodic execution of code in the background service worker. Could enable persistent tracking or automated actions if misused.
  • tabGroupsexpected: Provides access to chrome.tabGroups API, enabling tab organization features. No significant security implications unless combined with other permissions.
  • downloadsexpected: Grants access to chrome.downloads API, allowing file retrieval and saving. Could be misused for downloading malware or sensitive data if not properly controlled.
  • <all_urls>check this: Grants full read/write access to all URLs via chrome.declarativeNetRequest and content script injection capabilities. Allows interception of network requests, modification of page content, and potential data exfiltration from any site visited by the user. This permission is excessive for a screen recorder unless it's performing deep integration with many platforms. ⚠ 1

Data Exposure (Technical)

External domains contacted include api.vidyard.com, secure.vidyard.com, s3.amazonaws.com, avatar.vidyard.com, auth.vidyard.com, extension-backend.vidyard.com, rollbar.com, heapanalytics.com, goodbye.vidyard.com, and sso.vidyard.com. Data transmitted likely includes cookies, page content (for injection), keystrokes during recording, video metadata, and potentially user identifiers or session tokens depending on how the extension handles authentication.

Code Findings

InnerHTML assignmentMedium

Detected use of innerHTML assignment in a content script or injected code context (e.g., document.body.innerHTML = ...). If the value being assigned is derived from user input or external sources, this creates a potential XSS vector. The risk depends on whether the source is static or dynamic and how it's sanitized.

πŸ’‘ Common practice in extensions that modify page content dynamically based on user actions or data fetched from APIs.

HTTP request generationInfo

Code generates HTTP(S) requests using fetch or XMLHttpRequest APIs targeting various domains including api.vidyard.com and s3.amazonaws.com. These are likely used for uploading recordings, syncing data, or retrieving configuration settings. No evidence of insecure protocols like plain HTTP were found.

Keyboard event listenerHigh

Detected use of addEventListener('keydown', ...) in content scripts or background context. If this listener captures sensitive inputs like passwords or personal messages, it represents a significant risk for data theft. The extension may also be capturing global key combinations used to trigger screen recording features.

Code Analysis

  • Obfuscation: Standard minification observed; no heavy obfuscation techniques such as control flow flattening or string encoding detected.
  • Content Security Policy: Content Security Policy is present and restricts script execution within extension pages. It allows 'self' scripts and wasm-unsafe-eval, which may be acceptable for legitimate functionality but should still be reviewed carefully to ensure no unsafe inline code can execute.
  • Architecture: Uses Manifest V3 architecture with background service worker and content scripts injected into specific domains (e.g., Gmail, LinkedIn). The extension appears designed around a modular approach where different parts of the UI are handled by distinct content scripts. However, <all_urls> permission implies broad access that isn't clearly justified for core functionality.

Transparency

  • Developer: Developer name is not listed in the scan data; no clear indication of company or support links.
  • Privacy Policy: No privacy policy was found during scanning. This raises concerns about how user data may be handled, especially given the wide permissions and access to sensitive sites like Gmail and LinkedIn.
  • Code Visibility: Code appears bundled/minified with standard JavaScript compression techniques; not easily readable for independent auditing without decompilation tools.
  • Install Base: Installed by 300,000 users. Recent updates suggest ongoing maintenance.
Researcher Assessment

The presence of <all_urls> creates a high-risk surface area for potential misuse, especially when combined with content script injection capabilities and keyboard event listeners. The extension's architecture allows broad interception of network traffic and DOM manipulation across all domains, which could enable advanced persistent tracking or data exfiltration if exploited. While no direct evidence of malicious behavior was found, the risk profile is elevated due to excessive permissions and lack of transparency in developer identity or privacy policy.

Do more in Google Chrome with Adobe Acrobat PDF tools. View, fill, comment, sign, and try convert and compress tools.
Productivity/workflow
Block ads on YouTube and your favorite sites for free
Productivity/workflow
πŸ“¦
Remove ads on YouTube and everywhere else you browse.
Productivity/workflow
θΏ…ι›·δΈ‹θ½½ζ”―ζŒ
Productivity/workflow