Is Return YouTube Dislike safe?

Clean risk

Return YouTube Dislike injects an unsanitized version string from GitHub into the popup's innerHTML, enabling XSS if the remote file is tampered with.

When the extension popup opens, it fetches a manifest JSON file from raw.githubusercontent.com and writes the returned version field directly into the DOM via innerHTML without sanitization or integrity verification. If the GitHub repository or CDN serving that file is compromised, an attacker could inject arbitrary HTML or script into the popup, which runs in the extension's privileged context.

selivano.dv4.0.2Chrome Web Store
0Risk
Who publishes it

selivano.d - no other listings under this identity

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
selivano.d

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 4.0.2. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on youtube.com

    *://*.youtube.com/*

  • Store data in your browser

    storage

Updated 30 September 2026gebbhagfogifgggkldgodflihgfeippi