Is Youtube to Transcript safe?

Clean risk

Youtube to Transcript injects a script into the active tab letting its vocabulary.live iframe read and write the page DOM and localStorage.

When you click the toolbar button, the extension injects modal.js into the current page and opens an iframe pointing at vocabulary.live. That injected script listens for window messages and, on request, reads element text/HTML, reads, writes, and clears the page's localStorage, fills inputs, clicks elements, opens tabs, and writes to the clipboard, returning results to the iframe. The origin check guarding these actions is a substring/inclusion test that also accepts an empty origin, so it does not strictly confine which sender can trigger them.

Prius Labv1.2.1Chrome Web Store
0Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Data recipients

vocabulary.live
Updated 17 September 2026jjffnakjflkafmfmoaeodnfnoohlmecn