CRX aminer
Extension icon

DualPiP – Picture-in-Picture Player | Subtitles & AI Translation

Version 1.5.2 View in Chrome Web Store

Last scanned: about 4 hours ago

Extension Details

Developer: dualpip.cc
Rating: 4.7 ★ (52 ratings)
Users: 3,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension has a solid 4.7-star rating from 52 reviews and serves 3,000 users, indicating reasonable user satisfaction. The specific functionality (Picture-in-Picture with subtitles and AI translation) is clearly defined and legitimate. However, the relatively small user base and limited developer information (dualpip.cc) provide minimal reputation indicators for thorough trust assessment.

Concerns:

The combination of broad host permissions with webRequest capability creates significant privacy and security risks. While Picture-in-Picture functionality may require some web access, the <all_urls> permission grants excessive access to all websites you visit. The webRequest permission allows interception and modification of network traffic, which goes beyond typical PiP requirements. The unlimitedStorage permission, while potentially needed for subtitle caching, could be exploited for data hoarding. These permissions collectively enable comprehensive browsing surveillance and data collection capabilities that far exceed what's necessary for the stated functionality.

Recommendations:

Consider running this extension in a separate Chrome profile to isolate potential risks from your main browsing activities. Monitor your network traffic when the extension is active to detect any unexpected data transmission. Regularly review what data the extension has stored using Chrome's developer tools. If you only need basic PiP functionality, consider alternatives with more limited permissions. Given the high-risk permission combination, only install if the AI translation and subtitle features are essential to your workflow.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Medium-Risk Permission: unlimitedStorage
This extension has the unlimitedStorage permission. Can store unlimited data locally.