Web for TikTok
dcpmkllpnpfpojkjildgeoedikjbhodm
Risk Score
4.66
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- TikTok brand impersonation: developer domain wwevents.fun is not affiliated with TikTok; confirmed_owner=false.
- Broad host permissions (<all_urls>) combined with declarativeNetRequestWithHostAccess allows traffic interception on all sites.
- Install URL hijack: onInstalled redirects to chrome://flags/#enable-panels — abnormal behavior for a TikTok viewer.
- Privacy policy admits third-party data collection and sharing without retention disclosure.
- No developer name provided; 12 external JS hosts including social platforms unrelated to stated function.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true for TikTok; developer domain wwevents.fun has no affiliation.
- install_url_hijack crx install_url_hijack=true; target=chrome://flags/#enable-panels — atypical for entertainment extension.
- broad_host_permissions manifest <all_urls> in host_permissions alongside declarativeNetRequestWithHostAccess grants full network interception.
- js_external_hosts crx 12 external hosts including m.facebook.com, x.com, www.instagram.com, www.linkedin.com — scope mismatch.
- privacy_policy_third_party_sharing api Policy fetched; scope_extension=true but data_collection=true, third_party_sharing=true, retention=false.
- dom_xss_sink crx options/lib/mootools-core.js: innerHTML assignment from variable — DOM-XSS risk in bundled legacy library.
- no_developer_name store developer_name is empty string; only contact@wwevents.fun provided.
- verified_publisher_featured store verified_publisher=true and is_featured_by_google=true; partially offsets reputation concerns.
Permissions Breakdown
- declarativeNetRequestWithHostAccess high Can block/redirect network requests across all URLs — powerful traffic interception.
- <all_urls> (host_permissions) high Broad host access covering every site the user visits.
- scripting medium Programmatic script injection into pages; combined with <all_urls> is high-reach.
- declarativeNetRequest medium Request modification capability; lower risk than blocking variant but still notable.
- downloads medium Can trigger and manage file downloads without user gesture.
- activeTab low Scoped to current tab on user action; low standalone risk.
- storage low Local data persistence; low risk.
- unlimitedStorage low Removes storage quota; low direct harm.
- notifications low Can display system notifications; low risk.
- contextMenus low Adds right-click menu items; low risk.
- system.display low Read display configuration; low risk.
Pillar Scores
Permissions7.50
Reputation4.50
Network3.50
Webstore6.00
Maintenance1.50
Privacy2.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:26
Listing SHA
b9b81e65e632…
Force block
— not fired
Score recovered
no
Elapsed
26.5s