Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

TikTok Download Buttons

kcnchleajedobajlpgkcinfcdmdnfejd
Risk Score
4.02
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VideoDownloader
Installs 20,000
Rating 3.7
Last updated 2026-02-16 (4 months ago)
Manifest version MV3
CSP present ❌ no
Developer emy@five.sh
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's own generic policy (scope_extension=false, data_collection=true, third_party_sharing=true) — worst-case privacy disclosure for this extension.
  • TikTok brand impersonation: developer is not confirmed owner of TikTok, raising legitimacy concerns.
  • Content scripts on TikTok pages can read all page content including account data; no CSP to limit script execution.
  • Extension is a ToS-risk MediaDownloader targeting a major platform (TikTok); potential v3.1 rule (7) applicability.
  • Rating of 3.7 with no review red flags but no verified publisher or featured badge to establish trust.

Evidence

  • privacy_policy_generic store Privacy URL points to Google's account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy.
  • brand_impersonation store brand_mention.is_impersonation=true, confirmed_owner=false, not verified_publisher, not featured → +2.0 Reputation.
  • no_csp manifest content_security_policy=null on MV3; no additional network penalty but removes script-execution guardrails.
  • featured_by_google store is_featured_by_google=true → -2.0 Reputation (Follows recommended practices badge).
  • tos_violation_risk store VideoDownloader scraping TikTok (major platform) → +2.5 Webstore per v3.1 rule (7).
  • clean_code_scan crx code_findings_raw=[], obfuscation_score=0.0, js_external_hosts=[] — no malicious signals detected.
  • maintenance_recent store months_since_update=4 → +1.5 Maintenance (3-6 month band).
  • install_moderate store 20,000 installs → +1.0 Webstore (>10K threshold).

Permissions Breakdown

  • downloads medium Allows saving files to disk; appropriate for a video downloader but adds capability surface.
  • storage low Local key-value store; minimal risk on its own.
  • *://*.tiktok.com/* medium Scoped host access to TikTok; consistent with stated function but enables reading all TikTok page content.
  • https://tiktok.com/* low Redundant TikTok root-domain entry; same surface as above.
  • https://*.tiktokcdn.com/* medium Access to TikTok CDN; needed to resolve video URLs but broadens read surface.
  • https://*.tiktokv.com/* medium Access to TikTok video delivery domain; necessary for download but same concern.

Pillar Scores

Permissions2.50
Reputation5.50
Network2.00
Webstore4.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:47
Listing SHA 9832ce60e8c9…
Force block — not fired
Score recovered no
Elapsed 23.2s