Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Web for TikTok

dcpmkllpnpfpojkjildgeoedikjbhodm
Risk Score
4.66
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 10,000
Rating 3.6
Last updated 2025-11-08 (7 months ago)
Manifest version MV3
CSP present ✅ yes
Developer contact@wwevents.fun
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • TikTok brand impersonation: developer domain wwevents.fun is not affiliated with TikTok; confirmed_owner=false.
  • Broad host permissions (<all_urls>) combined with declarativeNetRequestWithHostAccess allows traffic interception on all sites.
  • Install URL hijack: onInstalled redirects to chrome://flags/#enable-panels — abnormal behavior for a TikTok viewer.
  • Privacy policy admits third-party data collection and sharing without retention disclosure.
  • No developer name provided; 12 external JS hosts including social platforms unrelated to stated function.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true for TikTok; developer domain wwevents.fun has no affiliation.
  • install_url_hijack crx install_url_hijack=true; target=chrome://flags/#enable-panels — atypical for entertainment extension.
  • broad_host_permissions manifest <all_urls> in host_permissions alongside declarativeNetRequestWithHostAccess grants full network interception.
  • js_external_hosts crx 12 external hosts including m.facebook.com, x.com, www.instagram.com, www.linkedin.com — scope mismatch.
  • privacy_policy_third_party_sharing api Policy fetched; scope_extension=true but data_collection=true, third_party_sharing=true, retention=false.
  • dom_xss_sink crx options/lib/mootools-core.js: innerHTML assignment from variable — DOM-XSS risk in bundled legacy library.
  • no_developer_name store developer_name is empty string; only contact@wwevents.fun provided.
  • verified_publisher_featured store verified_publisher=true and is_featured_by_google=true; partially offsets reputation concerns.

Permissions Breakdown

  • declarativeNetRequestWithHostAccess high Can block/redirect network requests across all URLs — powerful traffic interception.
  • <all_urls> (host_permissions) high Broad host access covering every site the user visits.
  • scripting medium Programmatic script injection into pages; combined with <all_urls> is high-reach.
  • declarativeNetRequest medium Request modification capability; lower risk than blocking variant but still notable.
  • downloads medium Can trigger and manage file downloads without user gesture.
  • activeTab low Scoped to current tab on user action; low standalone risk.
  • storage low Local data persistence; low risk.
  • unlimitedStorage low Removes storage quota; low direct harm.
  • notifications low Can display system notifications; low risk.
  • contextMenus low Adds right-click menu items; low risk.
  • system.display low Read display configuration; low risk.

Pillar Scores

Permissions7.50
Reputation4.50
Network3.50
Webstore6.00
Maintenance1.50
Privacy2.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:26
Listing SHA b9b81e65e632…
Force block — not fired
Score recovered no
Elapsed 26.5s