Is "大声朗读 - TTS 工具" on Chrome Web Store Safe to Install?

[email protected] · chrome · v1.0.0

核心功能: 🎯 一键朗读 自动识别并提取网页中的文本内容,点击播放按钮即可开始朗读,无需手动选择文本,智能提取主要阅读内容。 🎵 自然语音 使用浏览器原生语音合成技术,支持多种语言和语音包,清晰流畅的发音,接近真人朗读效果。 📖 实时高亮 朗读时自动高亮显示当前播放位置,跟随朗读进度实时滚动,清晰标注当前朗读的字符和段落。 🎛️ 灵活控制 播放、暂停、停止功能,支持随时中断和继续播放,简单直观的操作界面。 ⚙️ 个性化设置 可调节语速、音量、音调,支持选择不同语音包,设置自动保存,下次使用无需重新配置。 🌍 多语言支持 支持16种界面语言,包括中文、英文、日文、韩文、西班牙文、法文、德文等,支持多种语言的语音朗读,自动适配浏览器语言。

Risk Assessment

Analyzed
49.3
out of 100
MEDIUM

102 security findings detected across all analyzers

Chrome extension requesting 4 permissions

Severity Breakdown

0
Critical
18
High
84
Medium
0
Low
0
Info

Finding Categories

17
Malware Signatures
1
Obfuscation
81
IoC Indicators

YARA Rules Matched

7 rules(17 hits)
postinstall obfuscation postinstall file manipulation postinstall network communication postinstall file download postinstall system command NoUseWeakRandom postinstall crypto operations

Requested Permissions

4 permissions
https://*/*
Dangerous
http://*/*
Dangerous
activeTab
Medium
storage
Low

About This Extension

核心功能: 🎯 一键朗读 自动识别并提取网页中的文本内容,点击播放按钮即可开始朗读,无需手动选择文本,智能提取主要阅读内容。 🎵 自然语音 使用浏览器原生语音合成技术,支持多种语言和语音包,清晰流畅的发音,接近真人朗读效果。 📖 实时高亮 朗读时自动高亮显示当前播放位置,跟随朗读进度实时滚动,清晰标注当前朗读的字符和段落。 🎛️ 灵活控制 播放、暂停、停止功能,支持随时中断和继续播放,简单直观的操作界面。 ⚙️ 个性化设置 可调节语速、音量、音调,支持选择不同语音包,设置自动保存,下次使用无需重新配置。 🌍 多语言支持 支持16种界面语言,包括中文、英文、日文、韩文、西班牙文、法文、德文等,支持多种语言的语音朗读,自动适配浏览器语言。

Detailed Findings

18 total

YARA Rule Matches

7 rules

Indicators of Compromise

Network indicators, suspicious strings, and potential IoCs extracted during analysis

URLs
7
IP Addresses
1
Domains
73
Strings
81

All Indicators · 81

Domain
detected Domain: la.next

XIOC detected Domain: la.next

extracted_from_files

Domain
detected Domain: reactjs.org

XIOC detected Domain: reactjs.org

extracted_from_files

URL
detected URL: http://www.w3.org/2000/svg

XIOC detected URL: http://www.w3.org/2000/svg

extracted_from_files

URL
detected URL: http://www.w3.org/1999/xhtml

XIOC detected URL: http://www.w3.org/1999/xhtml

extracted_from_files

URL
detected URL: https://chromewebstore.google.com/detail/%E5%A4%A7%E5%A3%B0%E6%9C%97%E8%AF%BB%EF%BC%9A%E9%98%85%E8%AF%BB%E9%A1%B5%E9%9D%A2%E5%86%85%E5%AE%B9-%EF%BD%9C-listenquir/hhdbmmmklhjgobgnhmkboeoobopanfai

XIOC detected URL: https://chromewebstore.google.com/detail/%E5%A4%A7%E5%A3%B0%E6%9C%97%E8%AF%BB%EF%BC%9A%E9%98%85%E8%AF%BB%E9%A1%B5%E9%9D%A2%E5%86%85%E5%AE%B9-%EF%BD%9C-listenquir/hhdbmmmklhjgobgnhmkboeoobopanfai

extracted_from_files

Domain
detected Domain: o.storage

XIOC detected Domain: o.storage

extracted_from_files

Domain
detected Domain: h.current.play

XIOC detected Domain: h.current.play

extracted_from_files

Domain
detected Domain: microsoftedge.microsoft.com

XIOC detected Domain: microsoftedge.microsoft.com

extracted_from_files

URL
detected URL: https://clients2.google.com/service/update2/crx

XIOC detected URL: https://clients2.google.com/service/update2/crx

extracted_from_files

URL
detected URL: https://reactjs.org/docs/error-decoder.html?invariant=

XIOC detected URL: https://reactjs.org/docs/error-decoder.html?invariant=

extracted_from_files

URL
detected URL: http://www.w3.org/1999/xlink

XIOC detected URL: http://www.w3.org/1999/xlink

extracted_from_files

URL
detected URL: http://www.w3.org/XML/1998/namespace

XIOC detected URL: http://www.w3.org/XML/1998/namespace

extracted_from_files

Domain
detected Domain: e.map

XIOC detected Domain: e.map

extracted_from_files

Domain
detected Domain: a.storage

XIOC detected Domain: a.storage

extracted_from_files

Domain
detected Domain: chromewebstore.google.com

XIOC detected Domain: chromewebstore.google.com

extracted_from_files

Domain
detected Domain: c.map

XIOC detected Domain: c.map

extracted_from_files

Domain
detected Domain: popup.play

XIOC detected Domain: popup.play

extracted_from_files

Domain
detected Domain: window.open

XIOC detected Domain: window.open

extracted_from_files

Domain
detected Domain: e.data.name

XIOC detected Domain: e.data.name

extracted_from_files

Domain
detected Domain: a.call

XIOC detected Domain: a.call

extracted_from_files

Domain
detected Domain: performance.now

XIOC detected Domain: performance.now

extracted_from_files

Domain
detected Domain: u.now

XIOC detected Domain: u.now

extracted_from_files

Domain
detected Domain: s.now

XIOC detected Domain: s.now

extracted_from_files

Domain
detected Domain: l.storage

XIOC detected Domain: l.storage

extracted_from_files

Domain
detected Domain: f.map

XIOC detected Domain: f.map

extracted_from_files

Domain
detected Domain: globalthis.chrome

XIOC detected Domain: globalthis.chrome

extracted_from_files

Domain
detected Domain: r.next

XIOC detected Domain: r.next

extracted_from_files

Domain
detected Domain: l.name

XIOC detected Domain: l.name

extracted_from_files

Domain
detected Domain: a.style

XIOC detected Domain: a.style

extracted_from_files

Domain
detected Domain: d.memoizedprops.style

XIOC detected Domain: d.memoizedprops.style

extracted_from_files

Domain
detected Domain: r.is

XIOC detected Domain: r.is

extracted_from_files

Domain
detected Domain: e.top

XIOC detected Domain: e.top

extracted_from_files

Domain
detected Domain: o.call

XIOC detected Domain: o.call

extracted_from_files

Domain
detected Domain: h.call

XIOC detected Domain: h.call

extracted_from_files

Domain
detected Domain: d.next

XIOC detected Domain: d.next

extracted_from_files

Domain
detected Domain: n.data

XIOC detected Domain: n.data

extracted_from_files

IP
detected IP: ::

XIOC detected IP: ::

extracted_from_files

Domain
detected Domain: ll.next

XIOC detected Domain: ll.next

extracted_from_files

Domain
detected Domain: s.next

XIOC detected Domain: s.next

extracted_from_files

Domain
detected Domain: n.compare

XIOC detected Domain: n.compare

extracted_from_files

Domain
detected Domain: n.next

XIOC detected Domain: n.next

extracted_from_files

Domain
detected Domain: a.next

XIOC detected Domain: a.next

extracted_from_files

Domain
detected Domain: l.next

XIOC detected Domain: l.next

extracted_from_files

Domain
detected Domain: e.next

XIOC detected Domain: e.next

extracted_from_files

Domain
detected Domain: u.next

XIOC detected Domain: u.next

extracted_from_files

Domain
detected Domain: i.next

XIOC detected Domain: i.next

extracted_from_files

Domain
detected Domain: c.next

XIOC detected Domain: c.next

extracted_from_files

Domain
detected Domain: a.data

XIOC detected Domain: a.data

extracted_from_files

Domain
detected Domain: t.name

XIOC detected Domain: t.name

extracted_from_files

Domain
detected Domain: n.name

XIOC detected Domain: n.name

extracted_from_files

Domain
detected Domain: object.prototype.tostring.call

XIOC detected Domain: object.prototype.tostring.call

extracted_from_files

Domain
detected Domain: s.call

XIOC detected Domain: s.call

extracted_from_files

Domain
detected Domain: o.next

XIOC detected Domain: o.next

extracted_from_files

Domain
detected Domain: al.next

XIOC detected Domain: al.next

extracted_from_files

Domain
detected Domain: array.prototype.slice.call

XIOC detected Domain: array.prototype.slice.call

extracted_from_files

Domain
detected Domain: this.target

XIOC detected Domain: this.target

extracted_from_files

Domain
detected Domain: e.data

XIOC detected Domain: e.data

extracted_from_files

Domain
detected Domain: object.is

XIOC detected Domain: object.is

extracted_from_files

Domain
detected Domain: t.target

XIOC detected Domain: t.target

extracted_from_files

Domain
detected Domain: b.data

XIOC detected Domain: b.data

extracted_from_files

Domain
detected Domain: t.data

XIOC detected Domain: t.data

extracted_from_files

Domain
detected Domain: e.call

XIOC detected Domain: e.call

extracted_from_files

Domain
detected Domain: e.id-t.id

XIOC detected Domain: e.id-t.id

extracted_from_files

Domain
detected Domain: l.call

XIOC detected Domain: l.call

extracted_from_files

Domain
detected Domain: e.style

XIOC detected Domain: e.style

extracted_from_files

Domain
detected Domain: t.style

XIOC detected Domain: t.style

extracted_from_files

Domain
detected Domain: t.is

XIOC detected Domain: t.is

extracted_from_files

Domain
detected Domain: e.target

XIOC detected Domain: e.target

extracted_from_files

Domain
detected Domain: www.w3.org

XIOC detected Domain: www.w3.org

extracted_from_files

Domain
detected Domain: i.call

XIOC detected Domain: i.call

extracted_from_files

Domain
detected Domain: x.call

XIOC detected Domain: x.call

extracted_from_files

Domain
detected Domain: m.call

XIOC detected Domain: m.call

extracted_from_files

Domain
detected Domain: t.next

XIOC detected Domain: t.next

extracted_from_files

Domain
detected Domain: t.call

XIOC detected Domain: t.call

extracted_from_files

Domain
detected Domain: y.call

XIOC detected Domain: y.call

extracted_from_files

Domain
detected Domain: this.id

XIOC detected Domain: this.id

extracted_from_files

Domain
detected Domain: e.name

XIOC detected Domain: e.name

extracted_from_files

Domain
detected Domain: nodefilter.show

XIOC detected Domain: nodefilter.show

extracted_from_files

Domain
detected Domain: e.id

XIOC detected Domain: e.id

extracted_from_files

Domain
detected Domain: date.now

XIOC detected Domain: date.now

extracted_from_files

Domain
detected Domain: clients2.google.com

XIOC detected Domain: clients2.google.com

extracted_from_files

Security Analysis Summary

Security Analysis Overview

大声朗读 - TTS 工具 is a Chrome Web Store extension published by [email protected]. Version 1.0.0 has been analyzed by the Risky Plugins security platform, receiving a risk score of 49.3/100 (MEDIUM risk) based on 102 security findings.

Risk Assessment

This extension presents moderate security risk. Several findings were detected that may warrant attention. Users should carefully review the permissions and findings before installation.

Findings Breakdown

  • High: 18 finding(s)
  • Medium: 84 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

大声朗读 - TTS 工具 is published by [email protected] on the Chrome Web Store marketplace. The extension has approximately 12 users.

Recommendation

Exercise caution with this extension. Review the detailed findings and ensure the requested permissions align with the extension's stated functionality before installation.

Frequently Asked Questions