Is ShortKit – Level up your short-video experience safe?
ShortKit listens for postMessage on TikTok/Douyin pages without checking the sender, letting any page trigger a cookie-included fetch.
A script ShortKit injects into TikTok and Douyin pages listens for postMessage events and, without verifying who sent them, fetches whatever URL the message specifies using the page's own login cookies. Because any web page can send a message to a tab it merely holds a reference to, an unrelated site the user has open could use this listener to make the TikTok/Douyin tab issue a credentialed request to a URL of its choosing. The extension itself uses this same channel legitimately to fetch Douyin's API; the issue is that it doesn't check the request actually came from its own code.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
Who publishes itTiến Diệp - no other listings under this identity
Tiến Diệp - no other listings under this identity
What this publisher told the store about itself, and the other listings that told it the same thing.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.