Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

TikTok All Liked Videos Remover

eafmacjdgennnmhagdkdckgjokmnllci
Risk Score
5.07
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 10,000
Rating 4.2
Last updated 2026-02-13 (4 months ago)
Manifest version MV3
CSP present ❌ no
Developer contato@gabireze.com.br
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy — does not scope to this extension; data_collection and third_party_sharing admitted without extension context.
  • Brand impersonation: uses 'TikTok' in name without being confirmed owner; not verified publisher for TikTok brand.
  • cookies permission + scripting on tiktok.com enables full session token access to user's TikTok account.
  • innerHTML DOM-XSS sink in popup.js with no CSP — escalated risk under v3 rules.
  • No developer name disclosed; only email; description promises 'download' but lacks downloads permission.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true for 'tiktok'; confirmed_owner=false; not verified publisher.
  • generic_privacy_policy store Privacy policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • cookies_high_risk manifest cookies permission combined with host_permissions https://*.tiktok.com/* allows session token read/write.
  • dom_xss_no_csp crx dom_sink_innerhtml_userctrl in popup.js; csp_present=false — triggers +2.0 code quality escalation.
  • description_mismatch store Manifest description promises downloadable report but no 'downloads' permission declared.
  • no_developer_name store developer_name is empty string; identity relies solely on email contato@gabireze.com.br.
  • verified_publisher store verified_publisher=true; months_since_update=4, no CVEs, domain resolves — full -3.0 discount applies.
  • installs_10k store 10,000 installs; +1.0 webstore reach signal.

Permissions Breakdown

  • scripting medium Can inject JS into pages; scoped to tiktok.com via host_permissions.
  • tabs medium Can read tab URLs and titles; moderate surveillance surface.
  • cookies high Can read/write cookies; combined with tiktok.com host access allows session token access.
  • storage low Local extension storage only; low direct risk.
  • https://*.tiktok.com/* medium Host permission scoped to TikTok only; justified by stated function but enables cookie+script combo.

Pillar Scores

Permissions5.50
Reputation6.00
Network0.00
Webstore5.50
Maintenance1.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:28
Listing SHA 026b626fb854…
Force block — not fired
Score recovered no
Elapsed 25.4s