CRX aminer
Extension icon

SLyrics

Version 1.6.13 View in Chrome Web Store

Last scanned: about 4 hours ago

Extension Details

Developer: xianqiao.wang
Rating: 4.5 ★ (119 ratings)
Users: 4,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension has a decent user base of 4,000 users and maintains a solid 4.5-star rating from 119 reviews, suggesting users find it functional. However, the developer information is minimal with only a name provided (xianqiao.wang) and no company or detailed developer profile, which reduces transparency and accountability.

Concerns:

The extension's permissions are concerning given its apparent purpose as a lyrics display tool. The tabs permission allows access to all browser tab information, which seems excessive for simply showing lyrics on music streaming sites. The broad host permissions across multiple music platforms (Spotify, YouTube Music, Apple Music, etc.) create a large attack surface. The storage permission, while common, could be used to collect and store user data. The contextMenus permission adds another potential vector for unwanted interactions.

Most critically, for a lyrics extension, the tabs permission appears unnecessary and overly broad. A legitimate lyrics tool should only need to interact with the specific music streaming pages, not access information about all browser tabs.

Recommendations:

Consider running this extension in a separate Chrome profile to isolate it from your main browsing activities and sensitive accounts. Monitor the extension's behavior closely and consider alternatives with more limited permissions. If you must use it, avoid having sensitive tabs open simultaneously and regularly review what data the extension might be storing.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.