CRX aminer
Extension icon

YouTube Lyrics Extension – Real-Time Synced Lyrics | YT Lyrics

Version 1.0.9 View in Chrome Web Store

Last scanned: about 6 hours ago

Extension Details

Developer: https://ytlyrics-website-fbl7.vercel.app/
Rating: 4.8 ★ (19 ratings)
Users: 962

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors:

The extension has a decent rating of 4.8 stars from 19 reviews, though the user base is relatively small at 962 users. The developer uses a Vercel-hosted website, which is a legitimate hosting platform, but provides limited company information or transparency about the development team.

Concerns:

The primary concern is the broad host permissions that extend beyond YouTube to include external lyrics APIs (lrclib.net, lyrics.ovh) and all Vercel subdomains. While these permissions appear functionally necessary for fetching lyrics data, the wildcard Vercel permission (*.vercel.app/*) is overly broad and could potentially access other unrelated services. The extension's small user base and limited review history make it difficult to establish a strong trust foundation. The activeTab and storage permissions are appropriate for the extension's functionality.

Recommendations:

This extension appears legitimate for its stated purpose of displaying YouTube lyrics, but exercise caution due to the broad permissions. Consider running it in a separate Chrome profile if you're concerned about data exposure. Monitor the extension's behavior and revoke permissions if you notice any suspicious activity. Given the small user base, you might want to wait for broader adoption or look for more established alternatives with similar functionality and better-defined permission scopes.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.