Ad Library - Save Facebook TikTok - Foreplay
eaancnanphggbfliooildilcnjocggjm
Risk Score
4.08
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Brand impersonation: extension title mentions Facebook and TikTok; confirmed_owner=false.
- Privacy policy fetched but scope_extension=false with data_collection=true and third_party_sharing=true — worst-case generic policy.
- Content scripts injected on Facebook, Instagram, TikTok, LinkedIn, YouTube, and ChatGPT with no CSP — broad data-read surface.
- No CSP (MV3 default enforced, but csp_present=false increases exfil risk given broad host access).
- Developer name absent; description_promise.is_shell_pattern=true raises function-vs-permission scrutiny.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; brands facebook/tiktok in title; confirmed_owner=false; not verified publisher.
- privacy_policy_generic api scope_extension=false, data_collection=true, third_party_sharing=true — policy admits sharing but not scoped to extension.
- broad_host_permissions manifest Content scripts on 6 major platforms (FB, IG, TikTok, LinkedIn, YouTube, ChatGPT) plus foreplay.co R2.
- no_csp manifest content_security_policy=null; MV3 provides defaults but no explicit CSP declared.
- shell_pattern store description_promise.is_shell_pattern=true; developer_name empty; only 'storage' declared perm with broad host access.
- featured_by_google store is_featured_by_google=true; provides partial trust signal offsetting some reputation risk.
- no_bad_hosts_no_cves crx bad_host_hits=[], cve_findings_raw=[], code_findings_raw=[], obfuscation_score=0.0 — clean scan.
- js_external_hosts crx 12 external hosts including ads.tiktok.com, adstransparency.google.com, securetoken.google.com — all appear functionally justified.
Permissions Breakdown
- storage low Standard local data persistence; minimal risk.
- *://*.facebook.com/* high Content script on Facebook; can read/modify all page content including credentials.
- *://*.instagram.com/* high Content script on Instagram; broad read/write page access.
- *://*.tiktok.com/* high Content script on TikTok; broad read/write page access.
- *://*.linkedin.com/* high Content script on LinkedIn; can read professional/personal data.
- *://*.youtube.com/* medium Content script on YouTube; beyond stated ad-library saving function.
- *://*.chatgpt.com/* medium Content script on ChatGPT; not explained by ad-saving stated purpose.
- *://*.r2.foreplay.co/* low Dev-controlled CDN/storage domain; expected for saving ads.
Pillar Scores
Permissions3.50
Reputation5.50
Network3.50
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:28
Listing SHA
678e93f82216…
Force block
— not fired
Score recovered
no
Elapsed
24.2s