CRX aminer
Extension icon

YouTube PiP Extension

Version 1.0 View in Chrome Web Store

Last scanned: 1 day ago | force re-scan

Extension Details

Rating: 5.0 ★ (12 ratings)
Users: 3,000

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors:

The extension has a perfect 5.0 rating, though this is based on only 12 reviews which limits its reliability. With 3,000 users, it has modest adoption but lacks the widespread validation of more popular extensions. The absence of clear author and developer information raises transparency concerns, making it difficult to assess the creator's reputation or accountability.

Concerns:

The primary concern is the broad host permissions that extend beyond YouTube domains, which contradicts the extension's specific YouTube PiP functionality. While the scripting permission is appropriate for implementing picture-in-picture features, the overly broad host permissions create unnecessary security exposure. The limited user base and review count make it harder to verify the extension's behavior in practice. The lack of developer information prevents users from researching the creator's track record or contacting them with concerns.

Recommendations:

Consider running this extension in a separate Chrome profile to isolate potential risks from your main browsing environment. Before installation, verify that similar functionality isn't available through YouTube's native PiP feature or more established extensions with better transparency. Monitor the extension's behavior after installation and remove it if you notice any unexpected activity. Given the broad permissions, avoid using this extension while logged into sensitive accounts or browsing confidential information.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.