CRX aminer
Extension icon

TikTok Enhancer - Editing News & Re:TikTok

Version 2.0.3 View in Chrome Web Store

Last scanned: about 5 hours ago

Extension Details

Developer: editingnews.com
Rating: 4.1 ★ (53 ratings)
Users: 20,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension has a moderate user base of 20,000 users and a decent rating of 4.1 stars, which provides some community validation. However, the developer "editingnews.com" lacks clear company information or established reputation in the extension ecosystem. The connection between a news editing website and TikTok enhancement functionality raises questions about the developer's primary focus and expertise.

Concerns:

The extension exhibits several red flags that justify the critical risk assessment. The combination of tabs, downloads, and cookies permissions creates a powerful surveillance and data extraction capability that far exceeds what's necessary for typical TikTok enhancement features. The broad host permissions extending beyond TikTok domains to include localhost and the developer's own domains suggest potential data exfiltration pathways. Most concerning is the unsafe WebAssembly execution policy, which could hide malicious code and perform resource-intensive operations without detection. The permissions profile resembles that of data harvesting tools rather than simple enhancement utilities.

Recommendations:

Given the critical risk level, avoid installing this extension entirely. If TikTok enhancement features are essential, seek alternatives from established developers with transparent privacy policies and minimal permissions. If you must use this extension, run it in a completely isolated Chrome profile with no access to personal accounts, sensitive data, or other extensions. Monitor network activity and regularly clear cookies and stored data.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: downloads
This extension has the downloads permission. Can download files and access download history. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
Unsafe WebAssembly Execution
This extension's Content Security Policy allows 'wasm-unsafe-eval', which permits potentially dangerous WebAssembly code execution. This could be used to hide malicious code or perform CPU-intensive operations.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.