Export TikTok Followers
bdhcflkeglekljebdpanedpgeojpfefj
Risk Score
4.75
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy fetched but scope_extension=false + data_collection=true + third_party_sharing=true: admits broad sharing without scoping to this extension (→ Privacy +10.0).
- Brand impersonation: mentions TikTok, developer is not confirmed owner, gmail-based dev with no verified publisher (→ Reputation +2.0).
- webRequest on *://*.tiktok.com/* can intercept session tokens and follower data; combined with downloads permission enables silent exfiltration.
- Free-webmail developer (jfl913@gmail.com) with no verified business; operator cluster has 1 sibling extension under same fingerprint.
- No CSP (csp_present=false) on MV3 extension; identity permission can obtain Google auth tokens with unclear purpose for a TikTok export tool.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true, brands=['tiktok'], confirmed_owner=false, dev domain=gmail.com.
- privacy_policy_generic_with_data_sharing api scope_extension=false, data_collection=true, third_party_sharing=true → v3.5(D) Privacy +10.0.
- free_webmail_developer store Developer email jfl913@gmail.com; no verified publisher badge; no recognized org.
- operator_cluster_sibling api sibling_count=1 (kipefhbblcjblnkcnclpmlpfcflghooh) under same dev-email fingerprint.
- webRequest_on_tiktok manifest webRequest + host_permissions *://*.tiktok.com/* allows full request interception on TikTok.
- identity_permission manifest identity permission can fetch Google auth tokens; purpose unclear for TikTok follower export.
- no_csp crx content_security_policy=null on MV3; no CSP present.
- maintenance_6_12mo store months_since_update=11; falls in 6-12mo stale band (+3.5).
Permissions Breakdown
- scripting medium Allows JS injection into TikTok pages; medium scope since host_permissions are narrow.
- storage low Local data persistence; standard low-risk.
- unlimitedStorage low Enables large local storage; disk risk only.
- identity medium Can obtain user Google identity token; potential for auth-token abuse.
- webRequest high Can observe all network requests on tiktok.com including auth/session tokens.
- downloads medium Can trigger file downloads silently; could exfiltrate harvested data.
- *://*.tiktok.com/* high Content scripts + webRequest on all TikTok pages; full session/follower data visible.
Pillar Scores
Permissions6.50
Reputation7.50
Network3.50
Webstore6.00
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Operator Siblings (1)
Other extensions sharing this developer's compound fingerprint:
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:19
Listing SHA
50fe2407c101…
Force block
— not fired
Score recovered
no
Elapsed
24.1s