Is ShortKit – Level up your short-video experience safe?

Low risk

ShortKit listens for postMessage on TikTok/Douyin pages without checking the sender, letting any page trigger a cookie-included fetch.

A script ShortKit injects into TikTok and Douyin pages listens for postMessage events and, without verifying who sent them, fetches whatever URL the message specifies using the page's own login cookies. Because any web page can send a message to a tab it merely holds a reference to, an unrelated site the user has open could use this listener to make the TikTok/Douyin tab issue a credentialed request to a URL of its choosing. The extension itself uses this same channel legitimately to fetch Douyin's API; the issue is that it doesn't check the request actually came from its own code.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

Tiến Diệpv1.4.8Chrome Web Store
20Risk
Who publishes it

Tiến Diệp - no other listings under this identity

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Tiến Diệp
Registered address
P. Bạch Mai, Ha Noi, Hà Nội 100000, VN
Registered contact
Diep Van Tien

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Updated 30 September 2026kcihaacmobnfpcellccakhmbhkjdlkbf