Is Lean Library safe?

Low risk

Lean Library ships a hardcoded API Bearer token in its source and collects the user's IP address at startup for institution detection.

The extension bundles a static Bearer token in its background script, which is sent with every request to api.leanlibrary.app for logging actions and user feedback. On startup and every 15 minutes, the extension sends the user's IP address to llapi.leanlibrary.com to identify which library institution to associate with the user. Because the token is embedded in the distributed XPI file, anyone who extracts the package can replay authenticated API requests.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

Lean Libraryv2026.8.3Firefox Add-ons
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Data recipients

api.leanlibrary.appllapi.leanlibrary.com
Updated 17 September 2026amo-787965