Video Controls for TikTok
epmobcfgbmjijkhpimkmjhelcjkdfcoj
Risk Score
5.55
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- jquery@1.12.4 has 4 medium XSS CVEs; no CSP; version far behind fixed_in (3.5.0); MV3 but no CSP amplifies jQuery XSS risk.
- Privacy policy fetched but scope_extension==false with third_party_sharing==true; scores maximum privacy risk (10.0).
- Brand impersonation: TikTok brand used; developer not verified as TikTok owner; verified_publisher badge partially mitigates.
- Uninstall URL hijack to developer domain and install URL redirect both present; monetization/tracking indicators.
- Developer name field empty; extension 17 months stale; caps verified-publisher discount under v3.5 invariant 0c (months>18 threshold near).
Evidence
- cve_jquery_medium_x4 crx jquery@1.12.4 bundles CVE-2015-9251, CVE-2019-11358, CVE-2020-11022, CVE-2020-11023; all medium XSS; fixed in 3.5.0.
- no_csp_plus_jquery_cves crx csp_present=false + 4 medium CVEs in DOM-manipulation lib jquery; CVE v2 amplifier 1.5x applied to CVE pillar.
- privacy_policy_inadequate store Policy fetched; scope_extension=false, data_collection=false, third_party_sharing=true → generic policy admitting 3rd-party sharing.
- brand_impersonation store brand_mention.is_impersonation=true; TikTok brand in name; developer georgemike.com is not TikTok; verified_publisher=true reduces impact.
- uninstall_and_install_url_hijack crx install_url_hijack=true (to /options.html?install=1) and uninstall_url_hijack=true (to georgemike.com/videocontrolstiktok/uninstall/).
- script_src_dynamic_in_jquery crx Dynamic script creation found in jquery.min.js; part of jQuery JSONP transport; moderate risk given vulnerable version.
- verified_publisher_stale store verified_publisher=true but months_since_update=17; approaching 18mo cap threshold; discount not fully capped but noted.
- developer_name_empty store developer_name field is empty string; no 'Offered by' display name; partial +1.0 reputation penalty applied.
CVE Exposures (4)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@1.12.4 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@1.12.4 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@1.12.4 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@1.12.4 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- storage low Stores extension settings locally; minimal risk.
- host_permissions: *tiktok.com/* medium Scoped to TikTok only; matches stated function. Content script injection on all TikTok pages.
Pillar Scores
Permissions2.00
Reputation6.50
Network3.00
Webstore5.50
Maintenance6.00
Privacy10.00
Code Quality6.00
CVE Exposure6.00
Scoring History
| xx pfsssiedxa sssiedx | 5.02 | Medium | review | 2026-08-22 |
| 'fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 5.53 | Medium | review | 2026-08-22 |
| 'fsssiedxa$"sssiedx | 4.83 | Medium | review | 2026-08-22 |
| 5.28 | Medium | review | 2026-08-22 | |
| <fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 4.94 | Medium | review | 2026-08-22 |
| fsssiedxa<sssiedx | 4.93 | Medium | review | 2026-08-22 |
| fsssiedxasssiedx | 5.49 | Medium | review | 2026-08-20 |
| fsssiedxa | 4.87 | Medium | review | 2026-08-20 |
| sssieddrubricxsx | 5.12 | Medium | review | 2026-08-20 |
| v3.6 | 5.55 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:32
Listing SHA
0e4d4cb167f1…
Force block
— not fired
Score recovered
no
Elapsed
30.9s