Is "PiP+ - Subtitles & Danmaku" on Chrome Web Store Safe to Install?

[email protected] ยท chrome ยท v1.2.0

PiP+ transforms your viewing experience by bringing subtitles and danmaku into the Picture-in-Picture window. ๐Ÿš€ Key Features: โœ… Subtitles Support: Watch streaming videos with subtitles directly in the PiP window. No more missing dialogue! โœ… Danmaku Support: Renders real-time bullet comments in Picture-in-Picture mode for supported platforms. โœ… Window Memory (Pro): Automatically remembers your preferred PiP window size and position. Set it once, and it stays there. โœ… Video Dimming (Pro): Adjust the transparency of the PiP window to keep an eye on the video while focusing on your work. โœ… Speed Control (Pro): Extra playback speeds including 2.5x, 3x, and 5x for faster viewing. โœ… Volume Boost (Pro): Amplify quiet videos up to 300% volume. โœ… Screenshot (Pro): Capture video frames instantly with one click. ๐ŸŽ‰ BETA SPECIAL: All "Pro" features are currently FREE for all users during our public beta! ๐ŸŒ Platform Compatibility: Works with major streaming services and any website using standard HTML5 video players. ๐Ÿ”’ Privacy First: - 100% local processing - No data collection - No tracking - Open source: https://github.com/paradoxie/pip-plus-public ๐Ÿ“– Learn More: https://pipext.app ๐Ÿ” Privacy Policy: https://pipext.app/privacy ๐Ÿ’ฌ Support: [email protected]

Risk Assessment

Analyzed
62.52
out of 100
MEDIUM

109 security findings detected across all analyzers

Chrome extension requesting 3 permissions

Severity Breakdown

0
Critical
0
High
83
Medium
26
Low
0
Info

Finding Categories

8
Network
74
IoC Indicators

YARA Rules Matched

6 rules(26 hits)
postinstall crypto operations postinstall file manipulation postinstall network communication postinstall file download postinstall system command NoUseWeakRandom

Requested Permissions

3 permissions
<all_urls>

Access and modify data on every website you visit

Dangerous
activeTab
Medium
storage
Low

About This Extension

PiP+ transforms your viewing experience by bringing subtitles and danmaku into the Picture-in-Picture window. ๐Ÿš€ Key Features: โœ… Subtitles Support: Watch streaming videos with subtitles directly in the PiP window. No more missing dialogue! โœ… Danmaku Support: Renders real-time bullet comments in Picture-in-Picture mode for supported platforms. โœ… Window Memory (Pro): Automatically remembers your preferred PiP window size and position. Set it once, and it stays there. โœ… Video Dimming (Pro): Adjust the transparency of the PiP window to keep an eye on the video while focusing on your work. โœ… Speed Control (Pro): Extra playback speeds including 2.5x, 3x, and 5x for faster viewing. โœ… Volume Boost (Pro): Amplify quiet videos up to 300% volume. โœ… Screenshot (Pro): Capture video frames instantly with one click. ๐ŸŽ‰ BETA SPECIAL: All "Pro" features are currently FREE for all users during our public beta! ๐ŸŒ Platform Compatibility: Works with major streaming services and any website using standard HTML5 video players. ๐Ÿ”’ Privacy First: - 100% local processing - No data collection - No tracking - Open source: https://github.com/paradoxie/pip-plus-public ๐Ÿ“– Learn More: https://pipext.app ๐Ÿ” Privacy Policy: https://pipext.app/privacy ๐Ÿ’ฌ Support: [email protected]

Detailed Findings

34 total

YARA Rule Matches

6 rules

Indicators of Compromise

Network indicators, suspicious strings, and potential IoCs extracted during analysis

URLs
15
IP Addresses
12
Domains
54
Strings
74

All Indicators ยท 74

Domain
detected Domain: window.open

XIOC detected Domain: window.open

extracted_from_files

Domain
detected Domain: data.ga

XIOC detected Domain: data.ga

extracted_from_files

Domain
detected Domain: sender.tab

XIOC detected Domain: sender.tab

extracted_from_files

Domain
detected Domain: tab.id

XIOC detected Domain: tab.id

extracted_from_files

Domain
detected Domain: date.now

XIOC detected Domain: date.now

extracted_from_files

Domain
detected Domain: www.google-analytics.com

XIOC detected Domain: www.google-analytics.com

extracted_from_files

IP
detected IP: cc::

XIOC detected IP: cc::

extracted_from_files

IP
detected IP: ::a

XIOC detected IP: ::a

extracted_from_files

IP
detected IP: ::

XIOC detected IP: ::

extracted_from_files

Domain
detected Domain: config.ga

XIOC detected Domain: config.ga

extracted_from_files

IP
detected Domain: pipext.app

XIOC detected Domain: pipext.app

extracted_from_files

IP
detected IP: ::bef

XIOC detected IP: ::bef

extracted_from_files

URL
detected URL: https://pipext.app/usage?count=$

XIOC detected URL: https://pipext.app/usage?count=$

extracted_from_files

URL
detected URL: https://github.com/paradoxie/pip-plus-public

XIOC detected URL: https://github.com/paradoxie/pip-plus-public

extracted_from_files

URL
detected URL: https://pipext.app

XIOC detected URL: https://pipext.app

extracted_from_files

URL
detected URL: https://pipext.app/privacy

XIOC detected URL: https://pipext.app/privacy

extracted_from_files

URL
detected URL: https://pipext.app'

XIOC detected URL: https://pipext.app'

extracted_from_files

URL
detected URL: https://www.creem.io/payment/prod_608UfgZTYuAtJt80K8QFIt',

XIOC detected URL: https://www.creem.io/payment/prod_608UfgZTYuAtJt80K8QFIt',

extracted_from_files

Domain
detected Domain: creem.io

XIOC detected Domain: creem.io

extracted_from_files

URL
detected URL: http://www.w3.org/2000/svg

XIOC detected URL: http://www.w3.org/2000/svg

extracted_from_files

Domain
detected Domain: test-api.creem.io

XIOC detected Domain: test-api.creem.io

extracted_from_files

URL
detected URL: https://www.creem.io/payment/prod_608UfgZTYuAtJt80K8QFIt';

XIOC detected URL: https://www.creem.io/payment/prod_608UfgZTYuAtJt80K8QFIt';

extracted_from_files

Domain
detected Domain: github.com

XIOC detected Domain: github.com

extracted_from_files

IP
detected Email: [email protected]

XIOC detected Email: [email protected]

extracted_from_files

URL
detected URL: https://www.google-analytics.com/mp/collect';

XIOC detected URL: https://www.google-analytics.com/mp/collect';

extracted_from_files

URL
detected URL: https://api.creem.io',

XIOC detected URL: https://api.creem.io',

extracted_from_files

URL
detected URL: https://www.creem.io/payment/prod_xxxxxxxx',

XIOC detected URL: https://www.creem.io/payment/prod_xxxxxxxx',

extracted_from_files

URL
detected URL: https://test-api.creem.io',

XIOC detected URL: https://test-api.creem.io',

extracted_from_files

URL
detected URL: https://www.creem.io/test/payment/prod_1hOHX6nA0YBN5bLKUKF1JO',

XIOC detected URL: https://www.creem.io/test/payment/prod_1hOHX6nA0YBN5bLKUKF1JO',

extracted_from_files

Domain
detected Domain: p.bo

XIOC detected Domain: p.bo

extracted_from_files

Domain
detected Domain: ษตp.bo

XIOC detected Domain: ษตp.bo

extracted_from_files

Domain
detected Domain: b.bj

XIOC detected Domain: b.bj

extracted_from_files

Domain
detected Domain: clients2.google.com

XIOC detected Domain: clients2.google.com

extracted_from_files

Domain
detected Domain: feature-item.pro

XIOC detected Domain: feature-item.pro

extracted_from_files

Domain
detected Domain: badge.pro

XIOC detected Domain: badge.pro

extracted_from_files

Domain
detected Domain: section-header.pro

XIOC detected Domain: section-header.pro

extracted_from_files

Domain
detected Domain: jp.mm

XIOC detected Domain: jp.mm

extracted_from_files

Domain
detected Domain: j.tr

XIOC detected Domain: j.tr

extracted_from_files

Domain
detected Domain: l.fo

XIOC detected Domain: l.fo

extracted_from_files

Domain
detected Domain: k.ro

XIOC detected Domain: k.ro

extracted_from_files

Domain
detected Domain: m.li

XIOC detected Domain: m.li

extracted_from_files

Domain
detected Domain: idatr.lu

XIOC detected Domain: idatr.lu

extracted_from_files

Domain
detected Domain: d.bn

XIOC detected Domain: d.bn

extracted_from_files

Domain
detected Domain: a.click

XIOC detected Domain: a.click

extracted_from_files

Domain
detected Domain: videoinfo.video

XIOC detected Domain: videoinfo.video

extracted_from_files

Domain
detected Domain: stylesheet.id

XIOC detected Domain: stylesheet.id

extracted_from_files

Domain
detected Domain: chrome.storage

XIOC detected Domain: chrome.storage

extracted_from_files

Domain
detected Domain: www.w3.org

XIOC detected Domain: www.w3.org

extracted_from_files

Domain
detected Domain: link.download

XIOC detected Domain: link.download

extracted_from_files

Domain
detected Domain: link.click

XIOC detected Domain: link.click

extracted_from_files

Domain
detected Domain: twitter.com

XIOC detected Domain: twitter.com

extracted_from_files

Domain
detected Domain: x.com

XIOC detected Domain: x.com

extracted_from_files

Domain
detected Domain: twitch.tv

XIOC detected Domain: twitch.tv

extracted_from_files

Domain
detected Domain: e.target

XIOC detected Domain: e.target

extracted_from_files

Domain
detected Domain: video.play

XIOC detected Domain: video.play

extracted_from_files

URL
detected URL: https://clients2.google.com/service/update2/crx

XIOC detected URL: https://clients2.google.com/service/update2/crx

extracted_from_files

Domain
detected Domain: a.download

XIOC detected Domain: a.download

extracted_from_files

Domain
detected Domain: v.qq.com

XIOC detected Domain: v.qq.com

extracted_from_files

Domain
detected Domain: iqiyi.com

XIOC detected Domain: iqiyi.com

extracted_from_files

Domain
detected Domain: youku.com

XIOC detected Domain: youku.com

extracted_from_files

Domain
detected Domain: primevideo.com

XIOC detected Domain: primevideo.com

extracted_from_files

Domain
detected Domain: hbomax.com

XIOC detected Domain: hbomax.com

extracted_from_files

Domain
detected Domain: max.com

XIOC detected Domain: max.com

extracted_from_files

Domain
detected Domain: hulu.com

XIOC detected Domain: hulu.com

extracted_from_files

Domain
detected Domain: config.site

XIOC detected Domain: config.site

extracted_from_files

Domain
detected Domain: api.creem.io

XIOC detected Domain: api.creem.io

extracted_from_files

IP
detected Domain: pip-toast.show

XIOC detected Domain: pip-toast.show

extracted_from_files

Domain
detected Domain: youtube.com

XIOC detected Domain: youtube.com

extracted_from_files

Domain
detected Domain: netflix.com

XIOC detected Domain: netflix.com

extracted_from_files

Domain
detected Domain: disneyplus.com

XIOC detected Domain: disneyplus.com

extracted_from_files

Domain
detected Domain: bilibili.com

XIOC detected Domain: bilibili.com

extracted_from_files

Domain
detected Domain: www.creem.io

XIOC detected Domain: www.creem.io

extracted_from_files

Domain
detected Domain: window.global

XIOC detected Domain: window.global

extracted_from_files

URL
detected URL: https://www.google-analytics.com/mp/collect?measurement_id=$

XIOC detected URL: https://www.google-analytics.com/mp/collect?measurement_id=$

extracted_from_files

Security Analysis Summary

Security Analysis Overview

PiP+ - Subtitles & Danmaku is a Chrome Web Store extension published by [email protected]. Version 1.2.0 has been analyzed by the Risky Plugins security platform, receiving a risk score of 62.52/100 (MEDIUM risk) based on 109 security findings.

Risk Assessment

This extension presents high security risk. Significant concerns were identified during analysis. It is not recommended for use in sensitive or production environments without thorough review.

Findings Breakdown

  • Medium: 83 finding(s)
  • Low: 26 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

PiP+ - Subtitles & Danmaku is published by [email protected] on the Chrome Web Store marketplace. The extension has approximately 35 users.

Recommendation

This extension is not recommended for installation without thorough manual review. Consider alternatives with lower risk scores, or contact the developer to address the identified security concerns.

Frequently Asked Questions