CRX aminer
Extension icon

YouTube Watched Marker

Version 1.5.0 View in Chrome Web Store

Last scanned: about 5 hours ago

Extension Details

Developer: giraybal.com
Rating: 4.3 ★ (36 ratings)
Users: 2,000

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors: The extension has a reasonable user base of 2,000 users with a solid 4.3-star rating from 36 reviews, indicating generally positive user experiences. The developer domain (giraybal.com) appears to be a personal developer site. The extension's purpose of marking watched YouTube videos is legitimate and useful for users who want to track their viewing history.
Concerns: The primary concern is the broad host permissions for all YouTube domains (*://*.youtube.com/*), which technically allows the extension to access all YouTube pages and potentially collect extensive browsing data beyond what's necessary for its stated functionality. While the storage permission is appropriate for saving watched video markers, the combination with broad YouTube access creates potential for data collection. The relatively small user base and personal developer domain provide less assurance about long-term support and security practices compared to established companies.
Recommendations: This extension presents moderate risk due to its broad YouTube permissions. Consider running it in a separate Chrome profile if you're concerned about privacy. Monitor the extension's behavior and review permissions periodically. Since it only affects YouTube, the risk is contained to that platform. Users comfortable with YouTube-specific extensions and who find the functionality valuable may find the risk acceptable, but privacy-conscious users should evaluate whether the convenience justifies the broad access permissions.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.