The extension has a decent user base of 4,000 users and maintains a solid 4.5-star rating from 119 reviews, suggesting users find it functional. However, the developer information is minimal with only a name provided (xianqiao.wang) and no company or detailed developer profile, which reduces transparency and accountability.
The extension's permissions are concerning given its apparent purpose as a lyrics display tool. The tabs permission allows access to all browser tab information, which seems excessive for simply showing lyrics on music streaming sites. The broad host permissions across multiple music platforms (Spotify, YouTube Music, Apple Music, etc.) create a large attack surface. The storage permission, while common, could be used to collect and store user data. The contextMenus permission adds another potential vector for unwanted interactions.
Most critically, for a lyrics extension, the tabs permission appears unnecessary and overly broad. A legitimate lyrics tool should only need to interact with the specific music streaming pages, not access information about all browser tabs.
Consider running this extension in a separate Chrome profile to isolate it from your main browsing activities and sensitive accounts. Monitor the extension's behavior closely and consider alternatives with more limited permissions. If you must use it, avoid having sensitive tabs open simultaneously and regularly review what data the extension might be storing.
| https://github.com/getsentry/sentry-javascript/issues/2572. | https://caniuse.com/#feat=referrer-policy | |
| https://github.com/getsentry/raven-js/issues/1233 | https://124df8398d8b466fbcf09ec64bcfe144@o55145.ingest.sentry.io/5353517 | |
| https://addons.mozilla.org/en-US/firefox/addon/spotify-lyrics/ | https://chrome.google.com/webstore/detail/spotify-lyrics/mkjfooclbdgjdclepjeepbmmjaclipod/reviews | |
| https://microsoftedge.microsoft.com/addons/detail/spotify-lyrics/aiehldpoaeaidnljjimhbojpblkbembm | https://github.com/mantou132/Spotify-Lyrics | |
| https://github.com/mantou132/Spotify-Lyrics/issues | https://forms.gle/bUWyEqfSTCU9NEwEA | |
| https://open.scdn.co/cdn/fonts/CircularSpUIv3T-Light.afd9ab26.woff2 | https://open.scdn.co/cdn/fonts/CircularSpUIv3T-Light.2a78c017.woff | |
| https://open.scdn.co/cdn/fonts/CircularSpUIv3T-Light.89e4be2e.ttf | https://open.scdn.co/cdn/fonts/CircularSpUIv3T-Book.3466e0ec.woff2 | |
| https://open.scdn.co/cdn/fonts/CircularSpUIv3T-Book.ea8d19db.woff | https://open.scdn.co/cdn/fonts/CircularSpUIv3T-Book.a357677a.ttf | |
| https://open.scdn.co/cdn/fonts/CircularSpUIv3T-Bold.8d0a45cc.woff2 | https://open.scdn.co/cdn/fonts/CircularSpUIv3T-Bold.10e93738.woff | |
| https://open.scdn.co/cdn/fonts/CircularSpUIv3T-Bold.7eb7d0f7.ttf | https://github.com/mantou132/gem/issues/33 | |
| https://developer.mozilla.org/en-US/docs/Web/HTML/Global_attributes/exportparts | https://developer.mozilla.org/en-US/docs/Web/API/Web_Animations_API/Keyframe_Formats#attributes | |
| https://github.com/WICG/navigation-api#stakeholder-feedback | http://polymer.github.io/LICENSE.txt | |
| http://polymer.github.io/AUTHORS.txt | http://polymer.github.io/CONTRIBUTORS.txt | |
| http://polymer.github.io/PATENTS.txt | https://developer.mozilla.org/en-US/docs/Web/API/NamedNodeMap | |
| https://www.w3.org/TR/html5/syntax.html#elements-attributes | https://www.w3.org/TR/html5/infrastructure.html#space-characters | |
| https://github.com/tc39/proposal-array-is-template-object | https://github.com/Polymer/lit-html/issues/1048 | |
| https://stackoverflow.com/questions/43836886/failed-to-construct-customelement-error-when-javascript-file-is-placed-in-head | https://groups.google.com/a/chromium.org/g/blink-dev/c/JvpHoUfhJYE?pli=1 | |
| https://bugs.webkit.org/show_bug.cgi?id=215911 | https://bugzilla.mozilla.org/show_bug.cgi?id=1588763 | |
| https://github.com/microsoft/TypeScript/issues/21388#issuecomment-934345226 | https://github.com/whatwg/dom/issues/922 | |
| https://html.spec.whatwg.org/multipage/custom-elements.html#elementinternals | https://developers.google.com/analytics/devguides/collection/protocol/v1/devguide | |
| https://developers.google.com/analytics/devguides/collection/protocol/v1/parameters | https://www.google-analytics.com/collect | |
| http://mozilla.org/MPL/2.0/. | https://github.com/mozilla/webextension-polyfill/issues/130 | |
| https://clients2.google.com/service/update2/crx | https://raw.githubusercontent.com/extend-chrome/manifest-json-schema/main/schema/manifest.schema.json | |
| http://www.w3.org/1999/xhtml | https://github.com/sponsors/mantou132 | |
| https://www.buymeacoffee.com/mantou132 | https://bugzilla.mozilla.org/show_bug.cgi?id=1655937 | |
| https://github.com/WICG/local-font-access | https://bugzilla.mozilla.org/show_bug.cgi?id=1656732 | |
| https://bugs.chromium.org/p/chromium/issues/detail?id=390807 | https://github.com/mantou132/Spotify-Lyrics/issues/105 | |
| https://www.google.com/policies/privacy | https://support.google.com/analytics/answer/6004245 | |
| https://support.google.com/analytics/answer/181881 | https://sentry.io/privacy/ | |
| https://raw.githubusercontent.com/mantou132/Spotify-Lyrics/master/screenshot/lyrics-button.jpg | https://support.google.com/chrome_webstore/answer/2664769 | |
| https://chrome.google.com/webstore/detail/spotify-lyrics/mkjfooclbdgjdclepjeepbmmjaclipod | https://discord.com/invite/fQbzzdJ | |
| https://firebase.google.com/products/functions | https://files.xianqiao.wang/https://us-central1-spotify-lyrics-ef482.cloudfunctions.net | |
| https://raw.githubusercontent.com/mantou132/Spotify-Lyrics/master/screenshot/chrome-popup.jpg | https://raw.githubusercontent.com/mantou132/Spotify-Lyrics/master/screenshot/lrc-editor-in-spotify.jpg | |
| https://raw.githubusercontent.com/mantou132/Spotify-Lyrics/master/screenshot/options-in-spotify.jpg | https://support.google.com/chrome/answer/9658361 | |
| https://support.google.com/chrome_webstore/answer/3060053 | https://github.com/mantou132/Spotify-Lyrics/issues/35 | |
| http://www.w3.org/2000/svg | http://www.w3.org/1999/xlink | |
| https://github.com/mantou132/Spotify-Lyrics/issues/148 | https://files.xianqiao.wang/https://neteasecloudmusic.api.soraharu.com | |
| https://raw.githubusercontent.com/mantou132/Spotify-Lyrics/master/src/page/config.json?t= | https://open.spotify.com/service-worker.js | |
| https://lrclib.net/api | https://files.xianqiao.wang/https://api.genius.com | |
| https://files.xianqiao.wang/https://genius.com/songs/ | https://www.google.com/search?q= |
{ "name": "__MSG_extensionName__", "icons": { "48": "icons/48.png", "96": "icons/96.png", "128": "icons/128.png" }, "action": { "default_icon": { "48": "icons/48.png" }, "default_popup": "popup.html" }, "$schema": "https://raw.githubusercontent.com/extend-chrome/manifest-json-schema/main/schema/manifest.schema.json", "version": "1.6.13", "commands": { "toggle": { "global": true, "description": "Toggle lyrics", "suggested_key": { "mac": "Command+Shift+L", "default": "Ctrl+Shift+L" } } }, "background": { "service_worker": "background.js" }, "options_ui": { "page": "options.html" }, "update_url": "https://clients2.google.com/service/update2/crx", "description": "__MSG_extensionDescription__", "permissions": [ "scripting", "contextMenus", "storage", "tabs" ], "default_locale": "en", "content_scripts": [ { "js": [ "content.js" ], "run_at": "document_start", "matches": [ "*://open.spotify.com/*", "*://music.163.com/*", "*://www.deezer.com/*", "*://music.youtube.com/*", "*://music.apple.com/*", "*://listen.tidal.com/*" ] }, { "js": [ "options/index.js" ], "matches": [ "*://open.spotify.com/*", "*://music.163.com/*", "*://www.deezer.com/*", "*://music.youtube.com/*", "*://music.apple.com/*", "*://listen.tidal.com/*" ] } ], "host_permissions": [ "*://open.spotify.com/*", "*://music.163.com/*", "*://www.deezer.com/*", "*://music.youtube.com/*", "*://music.apple.com/*", "*://listen.tidal.com/*" ], "manifest_version": 3, "web_accessible_resources": [ { "matches": [ "*://*/*" ], "resources": [ "*" ] } ], "browser_specific_settings": { "gecko": { "id": "{d5bcc68d-856a-41e2-8021-d4c51f3b8e4a}", "strict_min_version": "78.0" } } }
ⓘ CRXaminer has partnered with our friends at Secure Annex to provide additional findings unique to their platform.
Secure Annex also analyzes extensions from other browsers, IDEs, and can continuously monitor.
This extension may not yet be analyzed by Secure Annex.