Is MAL-Sync safe?
Low risk
MAL-Sync embeds hardcoded OAuth client secrets for three third-party services in its extension bundle.
MAL-Sync stores OAuth client_secret values for Shikimori, MangaBaka, and Simkl directly in its JavaScript source files. These secrets are sent in POST requests to each service's token endpoint during authorization and token refresh flows. Any party who obtains a valid authorization code for these apps could use the embedded secret to exchange it for an access token appearing to originate from MAL-Sync.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
20Risk
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Data recipients
shikimori.onemangabaka.orgapi.simkl.com