Watch Party Works With Di Chrome extension icon

Watch Party Works With Di

🔍 Security Report Available
👥 40K+ users
📦 v4.0.33
💾 274KiB
📅 2026-01-19
View on Chrome Web Store

Chrome will indicate if you already have this installed.

Overview

Watch Party for use with Disney streaming - Watch together and chat

⚠️ Independent software - not affiliated with, endorsed by, or sponsored by Disney Media and Entertainment Distribution. Disney and Disney+ are trademarks of their respective owners.

This extension is part of the Quality Viewership Initiative, a collaborative effort to enhance the understanding of audience engagement. It collects anonymous, aggregated viewing insights to support creators and studios in improving the quality of their content. You can stop sharing your information at any time by switching the toggle on the options page.

Do you miss group movie marathons? Now you can do them online.

Watch your Disney Plus favorites with friends while staying on your comfy sofa. Thanks to live chat you can comment on what is happening on your screen and share your thoughts in real time.

No more fighting over the remote - everyone has the power to pause or rewind. While you may need to compromise on the movie choice, you are free to choose your snacks (and you do not have to share them).

How does it work?

Add the Watch Party extension to Chrome

Go to Disney+ and log in to your account

Click the puzzle piece icon in the Chrome toolbar

Pin the extension for quick access

Open the Party icon to copy or create a link

Share the invitation link (all participants need their own Disney Plus accounts)

Set your username in the chat panel

Make sure everyone is in sync

Pick a movie or series to watch together

Enjoy group streaming

Tags

Lifestyle/social lifestyle/social

Privacy Practices

Not being sold to third parties, outside of the approved use cases
Not being used or transferred for purposes that are unrelated to the item's core functionality
Not being used or transferred to determine creditworthiness or for lending purposes
✅ Version v4.0.34 was recently scanned.
v4.0.34 Info Scanned Feb 27, 2026

Security Analysis — Watch Party Works With Di

Analyzed v4.0.34 · Feb 27, 2026 · 40 JS files · 1414 KB scanned

Permissions

declarativeContent storage alarms https://*.disneyplus.com/*

Code Patterns Detected

Loads external scripts in service worker innerHTML assignment — potential XSS vector String.fromCharCode (obfuscation) charCodeAt (obfuscation) Makes XHR requests Uses Fetch API Creates script elements dynamically Reads browser storage Writes to browser storage Writes to clipboard Captures keystrokes Monitors storage changes Uses postMessage for cross-origin comms Sets up event listeners

External Connections

disney.api.edge.bamgrid.com disney.content.edge.bamgrid.com www.disneyplus.com gathermetrics.live github.com metricsmint.quest discover.disney.com awesomextensions.com ws.primevideoparty.com en.wikipedia.org bugzilla.mozilla.org stackoverflow.com +5 more

Package Contents 72 files · 1.4MB

📁_locales8KB
📁cs
{}messages.json558B
📁de
{}messages.json617B
📁en
{}messages.json524B
📁es
{}messages.json580B
📁fr
{}messages.json586B
📁hu
{}messages.json625B
📁ja
{}messages.json770B
📁ko
{}messages.json673B
📁pl
{}messages.json615B
📁pt_BR
{}messages.json579B
📁ro
{}messages.json629B
📁sk
{}messages.json566B
📁th
{}messages.json1010B
📁_metadata10KB
{}verified_contents.json10KB
📁lib162KB
📜config.js284B
📜global-helpers.js1KB
📜jquery.js87KBlarge
🎨normalize.css6KB
📜socketio.js67KBlarge
📜states.js153B
📁sidebar305KB
📁css1KB
🎨emoji.css1KB
📁js304KB
📜emoji.js304KBlarge
📁src976KB
📁background409KB
📜background.js562B
📜declarative-content.js507B
📜disney_background.min.js352KBlarge
📜messaging.js334B
📜onInstalled.js1KB
📜party.js3KB
📜typ.min.js51KBlarge
📁baner6KB
🎨baner.css2KB
📜baner.js3KB
🖼times-solid.svg637B
📁contentscripts527KB
📁actions8KB
📜bind-actions.js1KB
📜close.js1KB
📜pause.js1KB
📜play.js2KB
📜seek.js3KB
📁helpers3KB
📜helper.js1KB
📜ui-helper.js2KB
📁listener14KB
📜bootstrap.js433B
📜extension-messages.js239B
📜start-video-event.js744B
📜state-listener.js6KB
📜websocket.js7KB
📁ui7KB
🎨sidebar-host.css1KB
📜sidebar-host.js5KB
📜dh.js495KBlarge
📁optionPage3KB
📜optionPage.js641B
🎨options.css2KB
🌐options.html724B
📁popup11KB
📜geo.js3KB
📜init.js481B
📜popup-helper.js803B
📜popup-message-listener.js469B
🎨popup.css2KB
🌐popup.html3KB
📜ui-events.js1KB
📁sidebar19KB
📁css7KB
🎨member.css1023B
🎨message.css2KB
🎨nickname.css206B
🎨sidebar-playmode.css2KB
🎨sidebar.css2KB
📁js9KB
📜chat.js895B
📜message-handler.js2KB
📜nickname.js535B
📜sidebar-ui.js3KB
📜state-listener.js2KB
📜theme-listener.js630B
🌐set-nickname.html2KB
🌐sidebar.html2KB
🖼icon.png6KB
{}manifest.json2KB

What This Extension Does

Watch Party Works With Di is a Chrome extension that allows users to host Disney+ watch parties with friends, chat online, and share viewing insights anonymously. It solves the problem of missing group movie nights by enabling online co-viewing and discussion. This extension is suitable for anyone who wants to enjoy Disney+ content with others while staying on their comfortable sofa.

Permissions Explained

  • declarativeContentexpected: This permission allows the extension to display a puzzle piece icon in the Chrome toolbar, enabling users to easily access and use the Watch Party feature.
    Technical: The declarativeContent API is used to inject content into web pages, which can be a potential attack surface if compromised. However, in this case, it's justified for displaying the extension's icon and facilitating user interaction.
  • storageexpected: This permission enables the extension to store data locally on the user's device, such as viewing history and preferences.
    Technical: The storage API allows the extension to read and write browser storage, which can be a potential risk if not properly secured. However, in this case, it's justified for storing user-specific data and settings.
  • https://*.disneyplus.com/*expected: This permission allows the extension to interact with Disney+ content on specific domains, enabling features like co-viewing and chat functionality.
    Technical: The https://*.disneyplus.com/* permission scope is high-risk due to its broad nature, potentially exposing sensitive user data. However, in this case, it's justified for accessing Disney+ content and facilitating the Watch Party feature. ⚠ 1
  • alarmsexpected: This permission enables the extension to schedule background tasks, such as sending viewing insights or updating user settings.
    Technical: The alarms API allows the extension to run background scripts, which can be a potential risk if not properly secured. However, in this case, it's justified for scheduling tasks and maintaining user data.

Your Data

The extension accesses browser storage to store user-specific data and settings. It also sends anonymous viewing insights to the developer's servers, which are hosted on gathermetrics.live and metricsmint.quest.

Technical Details

The extension makes XHR requests to gathermetrics.live and metricsmint.quest, sending data such as viewing history and preferences. It also uses Fetch API for cross-origin communications. The extension reads browser storage using the storage API and writes to it using the same API.

Code Findings

Loads external scripts in service workerMedium

This behavior can potentially introduce security risks if the loaded scripts are malicious or outdated.

Technical: The extension loads external scripts using the service worker, which can be a potential attack surface. The scripts are loaded from unknown sources, and their integrity is not guaranteed.

💡 Legitimate extensions often load external scripts for functionality or performance reasons.

innerHTML assignment — potential XSS vectorMedium

This behavior can potentially lead to cross-site scripting (XSS) attacks if the extension is compromised or if user input is not properly sanitized.

Technical: The extension uses innerHTML assignment, which can be a potential XSS vector. The code is located in the content script and is used for rendering HTML content.

💡 Legitimate extensions often use innerHTML assignment for rendering dynamic content.

Captures keystrokesCritical

This behavior can potentially lead to sensitive data exposure or unauthorized access if the extension is compromised.

Technical: The extension uses the keyboard API to capture keystrokes, which can be a potential risk. The code is located in the content script and is used for monitoring user input.

💡 Legitimate extensions often use the keyboard API for functionality or performance reasons.

Bottom Line

Watch Party Works With Di is a Chrome extension that offers a convenient way to host Disney+ watch parties with friends. However, it has some security concerns due to its broad permission scope and potential data exposure risks. Users should exercise caution when using this extension and ensure they understand the implications of sharing their viewing insights anonymously.

Similar Extensions

More in Lifestyle/social →
Join Webex meetings using Google Chrome ™
Lifestyle/social

Line

3M+ users
Free messaging any time, anywhere
Lifestyle/social
Uncover the secrets to success behind your favorite YouTube videos.
Lifestyle/social