Starting analysis...
Version 3.2.0 View in Chrome Web Store
The extension has a reasonable user base of 40,000 users and maintains a solid 4.0-star rating from 487 reviews, indicating general user satisfaction. The developer provides a dedicated website (pockettube.io) which adds some legitimacy. However, the extension's purpose as a YouTube playlist manager should be considered when evaluating its permission requests.
The most significant concern is the identity permission, which allows access to user identity information - this seems excessive for a playlist management tool. The webRequest permission enables interception and modification of web traffic, which could be misused for data collection or injection of malicious content. While the host permissions are limited to YouTube domains (appropriate for the extension's function), the combination of identity access and web request interception creates potential privacy and security vulnerabilities. The unlimited storage permission, while potentially justified for managing large playlist collections, could be used to store excessive user data.
Given the high-risk permissions that seem disproportionate to the extension's stated functionality, consider running this extension in a separate Chrome profile to isolate potential risks. Monitor your YouTube account for any unusual activity after installation. Review the extension's privacy policy carefully to understand what data is collected and how it's used. Consider alternative playlist management tools that require fewer sensitive permissions if this functionality is available elsewhere.
| https://clients2.google.com/service/update2/crx | https://pockettube.io/ | |
| https://www.googleapis.com/auth/drive.appdata | https://www.googleapis.com/auth/youtube.readonly | |
| https://www.youtube.com | https://www.youtube.com/youtubei/v1/browse/edit_playlist?key= | |
| https://www.youtube.com/ | https://www.youtube.com/watch_videos?title= | |
| https://www.youtube.com/youtubei/v1/playlist/get_add_to_playlist?key= | https://www.youtube.com/channel/ | |
| https://www.youtube.com/youtubei/v1/browse?key= | https://www.youtube.com/youtubei/v1/playlist/create?key= | |
| https://www.youtube.com/youtubei/v1/playlist/delete?key= | https://www.youtube.com/watch?v= | |
| https://microsoftedge.microsoft.com/addons/detail/pockettube-youtube-playl/ehbcnddflnbfekidfnieclbpknhkelkj | https://apps.apple.com/us/app/id1592569440 | |
| https://addons.mozilla.org/en-US/firefox/addon/pockettube-youtube-playlist/ | https://chromewebstore.google.com/detail/pockettube-youtube-playli/bplnofkhjdphoihfkfcddikgmecfehdd/reviews#:~:text=Write%20a%20review | |
| https://pockettube.io/success-playlist.html?utm_source=opera | https://pockettube.io/success-playlist.html?utm_source=brave | |
| https://pockettube.io/success-playlist.html?utm_source=yandex | https://pockettube.io/success-playlist.html?utm_source=edge | |
| https://pockettube.io/success-playlist.html?utm_source=safari-new | https://pockettube.io/success-playlist.html?utm_source=firefox | |
| https://pockettube.io/success-playlist.html?utm_source=chrome | https://pockettube.io/remove-playlist.html?utm_source=opera | |
| https://pockettube.io/remove-playlist.html?utm_source=brave | https://pockettube.io/remove-playlist.html?utm_source=yandex | |
| https://pockettube.io/remove-playlist.html?utm_source=edge | https://pockettube.io/remove-playlist.html?utm_source=safari | |
| https://pockettube.io/remove-playlist.html?utm_source=firefox | https://pockettube.io/remove-playlist.html?utm_source=chrome | |
| https://api.mixpanel.com/track?ip=1&data= | https://i.yousub.info/upload | |
| https://imgur-apiv3.p.rapidapi.com/3/image | https://p.yousub.info/oauth/refresh-token?refresh_token= | |
| https://p.yousub.info/oauth/get-user-data | https://p.yousub.info/paddle/email | |
| https://p.yousub.info/backup | https://www.patreon.com/ysub?utm_source=context | |
| https://www.buymeacoffee.com/ysub?utm_source=context | https://www.reddit.com/r/pockettube/ | |
| https://www.youtube.com/channel/UCTVgSQTwWpHWIXC6EOh8vWw?sub_confirmation=1 | http://www.w3.org/2000/svg | |
| https://www.youtube.com/youtubei/v1/like/removelike?key= | https://www.youtube.com/api/stats/playback?ns=yt&cpn= | |
| https://www.youtube.com/feed/history/community_history | http://adamwdraper.github.com/Numeral-js/ | |
| https://github.com/facebook/regenerator/blob/main/LICENSE | https://www.youtube.com/getAccountSwitcherEndpoint | |
| https://www.youtube.com/youtubei/v1/browse | https://i.ytimg.com/vi/ | |
| http://www.example.com | https://1f4e44db2de071d3c698a0c26267e9b9@o416359.ingest.us.sentry.io/5310804 | |
| http://www.w3.org/1999/xlink | http://www.w3.org/1998/Math/MathML | |
| https://github.com/SortableJS/Vue.Draggable/blob/master/documentation/migrate.md#element-props | https://github.com/SortableJS/Vue.Draggable/blob/master/documentation/migrate.md#options-props | |
| https://github.com/zloirock/core-js/blob/v3.39.0/LICENSE | https://github.com/zloirock/core-js | |
| https://v2.vuetifyjs.com/getting-started/quick-start#bootstrapping-the-vuetify-object | https://github.com/vuetifyjs/vuetify/issues/4068 | |
| https://github.com/vuetifyjs/vuetify/releases/tag/v2.0.0#user-content-upgrade-guide | https://api.mixpanel.com | |
| https://www.flaticon.com/packs/music-52 | https://www.flaticon.com/packs/computer-gaming-3 | |
| https://www.flaticon.com/packs/news-journal-2 | https://www.flaticon.com/packs/rounded-multimedia | |
| https://www.flaticon.com/packs/healthy-lifestyle-22 | https://i.yousub.info/icon-search/ | |
| https://www.youtube.com/watch?v=JQCpYWp06sA&t=19s | https://youtube.com#ypm-patreon | |
| https://www.youtube.com/playlist?list= | https://github.com/phphe | |
| https://he-tree-vue.phphe.com | https://microsoftedge.microsoft.com/addons/detail/pockettube-youtube-subsc/klfeohnijmogpjoeenglhonjfiacajpp | |
| https://pockettube.io/install/PocketTube.dmg | https://addons.mozilla.org/en-US/firefox/addon/youtube-subscription-groups/ | |
| https://chrome.google.com/webstore/detail/pockettube-youtube-subscr/kdmnjgijlmjgmimahnillepgcgeemffb | https://www.patreon.com/join/ysub/checkout?rid=3745845 |
{ "key": "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAkxzL19Hk2fXGUg6lEw70iKrMXC9kP4Aq4YChYF7UDCqChYRSufSpKgicf3nu5TTXKtjW/2UgHoPd1hXmF4rthA26YM7C1TMJ7kahyLL57OJqgNlpV7Sr1Ba4bWHjzr3450YpmKtz6S2EjYFqQ5Dsy8OQBV3plxKcttTtVmDSExDCUhwH6ChZIps+wK/VHNBD4yRy1B+7DMb157yldQTGa8kqfJXCZ1edXkjOrfnxATU1XNhcQL+kPOpx93fdoWgqr7NCdLe1nBMi/7ChQAxhY2IOZkY4QKDxTIbrmn9i5xRjxTSK1b/MipcwY1wiVrVZlmJpQhGMCfITYgLEkU5BmQIDAQAB", "name": "__MSG_name__", "icons": { "16": "icon/icon_16.png", "48": "icon/icon_48.png", "128": "icon/icon_128.png" }, "action": { "default_icon": { "16": "icon/icon_16.png", "48": "icon/icon_48.png", "128": "icon/icon_128.png" }, "default_popup": "/pockettube-app/dist/index.html", "default_title": "PocketTube: Youtube PlayList Manager" }, "author": "Dmitry Nabok", "oauth2": { "scopes": [ "profile", "https://www.googleapis.com/auth/drive.appdata", "https://www.googleapis.com/auth/youtube.readonly" ], "client_id": "579336474196-vvopcc4b0to7aal97pab6pgpks89qb8b.apps.googleusercontent.com" }, "version": "3.2.0", "background": { "service_worker": "/build/background.js" }, "short_name": "YSM", "update_url": "https://clients2.google.com/service/update2/crx", "description": "__MSG_description__", "permissions": [ "alarms", "storage", "unlimitedStorage", "identity", "contextMenus", "webRequest" ], "homepage_url": "https://pockettube.io/", "options_page": "/pockettube-app/dist/index.html", "default_locale": "en", "content_scripts": [ { "js": [ "/build/app.js", "/purify2.min.js" ], "css": [ "context.css" ], "run_at": "document_start", "matches": [ "https://*.youtube.com/*" ] } ], "host_permissions": [ "https://*.youtube.com/*" ], "manifest_version": 3, "web_accessible_resources": [ { "matches": [ "https://*.youtube.com/*" ], "resources": [ "/build/ut.js", "/purify2.min.js", "/pockettube-app/dist/*", "/page/login.html", "icon/*" ] } ] }
ⓘ CRXaminer has partnered with our friends at Secure Annex to provide additional findings unique to their platform.
Secure Annex also analyzes extensions from other browsers, IDEs, and can continuously monitor.
This extension may not yet be analyzed by Secure Annex.