Desktop for Tiktok online
mjebgmffggocefpegddahkcnpllfmaid
Risk Score
3.54
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Brand impersonation: TikTok name used without ownership, confirmed is_impersonation=true.
- Privacy policy admits data collection and third-party sharing but is not scoped to this extension (D rule: +10.0).
- No developer display name listed; identity accountability is weak.
- Rating of 3.4 indicates user dissatisfaction though rating_count is unknown.
- No CSP on MV3 extension contacting external host www.runapps.org.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true, brands_mentioned=[tiktok], confirmed_owner=false.
- privacy_policy_generic_with_data_sharing api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → D rule +10.0.
- no_developer_name store developer_name is empty string; no display identity accountability.
- verified_publisher store verified_publisher=true; no stale/CVE/unresolved-domain cap triggers, discount applies.
- external_host_contact crx js_external_hosts=[www.runapps.org]; MV3 so no +2.0 MV2/no-CSP network penalty.
- low_rating store Rating 3.4; rating_count unknown so <50 threshold for +1.0 cannot be confirmed; not applied.
- no_cve_findings crx cve_findings_raw=[] and js_libraries_detected=[]; CVE pillar=0.0.
- operator_cluster_clean api sibling_count=0; no cluster amplification applied.
Permissions Breakdown
- storage low Local data persistence only; low standalone risk.
Pillar Scores
Permissions0.30
Reputation7.00
Network0.00
Webstore2.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:55
Listing SHA
5151384bf1a3…
Force block
— not fired
Score recovered
no
Elapsed
17.3s