CRX aminer
Extension icon

PocketTube: Youtube PlayList Manager

Version 2.17.7 View in Chrome Web Store

Last scanned: about 2 months ago | force re-scan

Extension Details

Developer: https://pockettube.io/
Rating: 4.1 ★ (438 ratings)
Users: 30,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors: The extension has a moderate user base of 30,000 users and a decent 4.1-star rating from 438 reviews, suggesting legitimate functionality. The developer maintains a dedicated website (pockettube.io) which adds some credibility. However, the extension's purpose as a YouTube playlist manager doesn't fully justify some of the powerful permissions it requests.
Concerns: The identity permission is particularly concerning as it can access personal authentication information, which seems unnecessary for playlist management. The webRequest permission allows intercepting and modifying web traffic, creating potential for data theft or malicious modifications. While the host permissions are limited to YouTube domains, they're still quite broad. The unlimited storage permission could be used to hoard excessive data on your device.

The combination of identity access, web request interception, and broad YouTube permissions creates a significant attack surface. An attacker could potentially access your Google account information, monitor your YouTube activity, or inject malicious content.

Recommendations: Consider running this extension in a separate Chrome profile to isolate it from your main browsing session and other extensions. Before installing, verify that the advanced permissions are actually necessary for the playlist management features you need. Monitor the extension's behavior and remove it if you notice unusual network activity or performance issues. Consider alternative playlist managers with more limited permissions if this functionality isn't essential.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: identity
This extension has the identity permission. Can access your identity information. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Medium-Risk Permission: unlimitedStorage
This extension has the unlimitedStorage permission. Can store unlimited data locally.