Is Lean Library safe?
Lean Library ships a hardcoded API Bearer token in its source and collects the user's IP address at startup for institution detection.
The extension bundles a static Bearer token in its background script, which is sent with every request to api.leanlibrary.app for logging actions and user feedback. On startup and every 15 minutes, the extension sends the user's IP address to llapi.leanlibrary.com to identify which library institution to associate with the user. Because the token is embedded in the distributed XPI file, anyone who extracts the package can replay authenticated API requests.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.