TikTok All Liked Videos Remover
eafmacjdgennnmhagdkdckgjokmnllci
Risk Score
5.07
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic policy — does not scope to this extension; data_collection and third_party_sharing admitted without extension context.
- Brand impersonation: uses 'TikTok' in name without being confirmed owner; not verified publisher for TikTok brand.
- cookies permission + scripting on tiktok.com enables full session token access to user's TikTok account.
- innerHTML DOM-XSS sink in popup.js with no CSP — escalated risk under v3 rules.
- No developer name disclosed; only email; description promises 'download' but lacks downloads permission.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true for 'tiktok'; confirmed_owner=false; not verified publisher.
- generic_privacy_policy store Privacy policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- cookies_high_risk manifest cookies permission combined with host_permissions https://*.tiktok.com/* allows session token read/write.
- dom_xss_no_csp crx dom_sink_innerhtml_userctrl in popup.js; csp_present=false — triggers +2.0 code quality escalation.
- description_mismatch store Manifest description promises downloadable report but no 'downloads' permission declared.
- no_developer_name store developer_name is empty string; identity relies solely on email contato@gabireze.com.br.
- verified_publisher store verified_publisher=true; months_since_update=4, no CVEs, domain resolves — full -3.0 discount applies.
- installs_10k store 10,000 installs; +1.0 webstore reach signal.
Permissions Breakdown
- scripting medium Can inject JS into pages; scoped to tiktok.com via host_permissions.
- tabs medium Can read tab URLs and titles; moderate surveillance surface.
- cookies high Can read/write cookies; combined with tiktok.com host access allows session token access.
- storage low Local extension storage only; low direct risk.
- https://*.tiktok.com/* medium Host permission scoped to TikTok only; justified by stated function but enables cookie+script combo.
Pillar Scores
Permissions5.50
Reputation6.00
Network0.00
Webstore5.50
Maintenance1.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:28
Listing SHA
026b626fb854…
Force block
— not fired
Score recovered
no
Elapsed
25.4s