TikTok Analytics By EchoTik
napmaafilgfpfohgpjokahilhgmkkfjo
Risk Score
4.15
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy fetched but scope_extension==false with data_collection+third_party_sharing==true: effectively admits broad data sharing without scoping to this extension (+10.0 privacy).
- Brand impersonation: mentions TikTok in title/content scripts but confirmed_owner==false and developer domain echosell.com does not resolve.
- No CSP on MV3 extension with innerHTML DOM-XSS sinks and new Function() constructor across 3 JS files.
- Content scripts injected into live TikTok affiliate and shop domains can read session tokens and affiliate data.
- Developer domain echosell.com does not resolve; verified-publisher discount capped per v3.5 invariant 0c.
Evidence
- privacy_policy_generic_admits_sharing api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 rule D).
- brand_impersonation store brand_mention.is_impersonation=true for TikTok; confirmed_owner=false; verified+featured → +1.0 reputation (v3.2 rule 9).
- developer_domain_not_resolving api echosell.com resolves=false; caps verified-publisher discount at -1.0 per v3.5 invariant 0c.
- dom_xss_no_csp crx 3x dom_sink_innerhtml_userctrl + csp_present=false → each triggers +2.0 (FIX B); capped at code_quality 5.0.
- function_constructor crx new Function() constructor in options and popup JS (+2.5 code quality).
- content_scripts_tiktok_affiliate manifest Scripts injected into affiliate.tiktok.com, shop.tiktok.com, oec-api.tiktokv.com — high-value session data surfaces.
- verified_publisher_featured store verified_publisher=true, is_featured_by_google=true; reputation mitigated but capped due to non-resolving domain.
- no_csp_mv3 manifest content_security_policy=null on MV3; no additional network penalty (MV3 default strict), but amplifies code risk.
Permissions Breakdown
- storage low Local key-value storage only; no cross-origin or user-data exfil risk on its own.
- content_scripts: http://echotik.live/*, https://echotik.live/* medium Script injection into dev-controlled domain; echotik.live domain does not resolve.
- content_scripts: https://affiliate.tiktok.com/*, https://affiliate.tiktokglobalshop.com/* high Script runs on TikTok affiliate pages — can read session tokens, affiliate data.
- content_scripts: https://www.tiktok.com/*, https://shop.tiktok.com/*, https://oec-api.tiktokv.com/* high Broad script injection across TikTok properties including API endpoints.
Pillar Scores
Permissions3.00
Reputation5.50
Network2.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-15 14:30
Listing SHA
41ad8abb09e8…
Force block
— not fired
Score recovered
no
Elapsed
32.1s