Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Video Controls for TikTok

epmobcfgbmjijkhpimkmjhelcjkdfcoj
Risk Score
5.55
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 2,000
Rating 3.9
Last updated 2025-01-29 (19 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@georgemike.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • jquery@1.12.4 has 4 medium XSS CVEs; no CSP; version far behind fixed_in (3.5.0); MV3 but no CSP amplifies jQuery XSS risk.
  • Privacy policy fetched but scope_extension==false with third_party_sharing==true; scores maximum privacy risk (10.0).
  • Brand impersonation: TikTok brand used; developer not verified as TikTok owner; verified_publisher badge partially mitigates.
  • Uninstall URL hijack to developer domain and install URL redirect both present; monetization/tracking indicators.
  • Developer name field empty; extension 17 months stale; caps verified-publisher discount under v3.5 invariant 0c (months>18 threshold near).

Evidence

  • cve_jquery_medium_x4 crx jquery@1.12.4 bundles CVE-2015-9251, CVE-2019-11358, CVE-2020-11022, CVE-2020-11023; all medium XSS; fixed in 3.5.0.
  • no_csp_plus_jquery_cves crx csp_present=false + 4 medium CVEs in DOM-manipulation lib jquery; CVE v2 amplifier 1.5x applied to CVE pillar.
  • privacy_policy_inadequate store Policy fetched; scope_extension=false, data_collection=false, third_party_sharing=true → generic policy admitting 3rd-party sharing.
  • brand_impersonation store brand_mention.is_impersonation=true; TikTok brand in name; developer georgemike.com is not TikTok; verified_publisher=true reduces impact.
  • uninstall_and_install_url_hijack crx install_url_hijack=true (to /options.html?install=1) and uninstall_url_hijack=true (to georgemike.com/videocontrolstiktok/uninstall/).
  • script_src_dynamic_in_jquery crx Dynamic script creation found in jquery.min.js; part of jQuery JSONP transport; moderate risk given vulnerable version.
  • verified_publisher_stale store verified_publisher=true but months_since_update=17; approaching 18mo cap threshold; discount not fully capped but noted.
  • developer_name_empty store developer_name field is empty string; no 'Offered by' display name; partial +1.0 reputation penalty applied.

CVE Exposures (4)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@1.12.4 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@1.12.4 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@1.12.4 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.12.4 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • storage low Stores extension settings locally; minimal risk.
  • host_permissions: *tiktok.com/* medium Scoped to TikTok only; matches stated function. Content script injection on all TikTok pages.

Pillar Scores

Permissions2.00
Reputation6.50
Network3.00
Webstore5.50
Maintenance6.00
Privacy10.00
Code Quality6.00
CVE Exposure6.00

Scoring History

xx pfsssiedxa sssiedx 5.02 Medium review 2026-08-22
&#x27;fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 5.53 Medium review 2026-08-22
&#x27;fsssiedxa$"sssiedx 4.83 Medium review 2026-08-22
5.28 Medium review 2026-08-22
<fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 4.94 Medium review 2026-08-22
fsssiedxa<sssiedx 4.93 Medium review 2026-08-22
fsssiedxasssiedx 5.49 Medium review 2026-08-20
fsssiedxa 4.87 Medium review 2026-08-20
sssieddrubricxsx 5.12 Medium review 2026-08-20
v3.6 5.55 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:32
Listing SHA 0e4d4cb167f1…
Force block — not fired
Score recovered no
Elapsed 30.9s