Watch Party Works With Di
🔍 Security Report Available View on Chrome Web StoreChrome will indicate if you already have this installed.
Overview
Watch Party for use with Disney streaming - Watch together and chat
⚠️ Independent software - not affiliated with, endorsed by, or sponsored by Disney Media and Entertainment Distribution. Disney and Disney+ are trademarks of their respective owners.
This extension is part of the Quality Viewership Initiative, a collaborative effort to enhance the understanding of audience engagement. It collects anonymous, aggregated viewing insights to support creators and studios in improving the quality of their content. You can stop sharing your information at any time by switching the toggle on the options page.
Do you miss group movie marathons? Now you can do them online.
Watch your Disney Plus favorites with friends while staying on your comfy sofa. Thanks to live chat you can comment on what is happening on your screen and share your thoughts in real time.
No more fighting over the remote - everyone has the power to pause or rewind. While you may need to compromise on the movie choice, you are free to choose your snacks (and you do not have to share them).
How does it work?
Add the Watch Party extension to Chrome
Go to Disney+ and log in to your account
Click the puzzle piece icon in the Chrome toolbar
Pin the extension for quick access
Open the Party icon to copy or create a link
Share the invitation link (all participants need their own Disney Plus accounts)
Set your username in the chat panel
Make sure everyone is in sync
Pick a movie or series to watch together
Enjoy group streaming
Tags
Privacy Practices
Security Analysis — Watch Party Works With Di
Permissions
Code Patterns Detected
External Connections
Package Contents 72 files · 1.4MB
What This Extension Does
Watch Party Works With Di is a Chrome extension that allows users to host Disney+ watch parties with friends, chat online, and share viewing insights anonymously. It solves the problem of missing group movie nights by enabling online co-viewing and discussion. This extension is suitable for anyone who wants to enjoy Disney+ content with others while staying on their comfortable sofa.
Permissions Explained
- declarativeContentexpected: This permission allows the extension to display a puzzle piece icon in the Chrome toolbar, enabling users to easily access and use the Watch Party feature.
Technical: The declarativeContent API is used to inject content into web pages, which can be a potential attack surface if compromised. However, in this case, it's justified for displaying the extension's icon and facilitating user interaction. - storageexpected: This permission enables the extension to store data locally on the user's device, such as viewing history and preferences.
Technical: The storage API allows the extension to read and write browser storage, which can be a potential risk if not properly secured. However, in this case, it's justified for storing user-specific data and settings. - https://*.disneyplus.com/*expected: This permission allows the extension to interact with Disney+ content on specific domains, enabling features like co-viewing and chat functionality.
Technical: The https://*.disneyplus.com/* permission scope is high-risk due to its broad nature, potentially exposing sensitive user data. However, in this case, it's justified for accessing Disney+ content and facilitating the Watch Party feature. ⚠ 1 - alarmsexpected: This permission enables the extension to schedule background tasks, such as sending viewing insights or updating user settings.
Technical: The alarms API allows the extension to run background scripts, which can be a potential risk if not properly secured. However, in this case, it's justified for scheduling tasks and maintaining user data.
Your Data
The extension accesses browser storage to store user-specific data and settings. It also sends anonymous viewing insights to the developer's servers, which are hosted on gathermetrics.live and metricsmint.quest.
Technical Details
Code Findings
This behavior can potentially introduce security risks if the loaded scripts are malicious or outdated.
Technical: The extension loads external scripts using the service worker, which can be a potential attack surface. The scripts are loaded from unknown sources, and their integrity is not guaranteed.
💡 Legitimate extensions often load external scripts for functionality or performance reasons.
This behavior can potentially lead to cross-site scripting (XSS) attacks if the extension is compromised or if user input is not properly sanitized.
Technical: The extension uses innerHTML assignment, which can be a potential XSS vector. The code is located in the content script and is used for rendering HTML content.
💡 Legitimate extensions often use innerHTML assignment for rendering dynamic content.
This behavior can potentially lead to sensitive data exposure or unauthorized access if the extension is compromised.
Technical: The extension uses the keyboard API to capture keystrokes, which can be a potential risk. The code is located in the content script and is used for monitoring user input.
💡 Legitimate extensions often use the keyboard API for functionality or performance reasons.
Watch Party Works With Di is a Chrome extension that offers a convenient way to host Disney+ watch parties with friends. However, it has some security concerns due to its broad permission scope and potential data exposure risks. Users should exercise caution when using this extension and ensure they understand the implications of sharing their viewing insights anonymously.