Is taplio x safe?

Medium risk

Taplio X is medium risk. Taplio X installs 13 declarativeNetRequest rules blocking LinkedIn's bot-detection, CSP reporting, and telemetry endpoints. Dynamic analysis captured 5 blocked POSTs to /platform-telemetry/apfcDf and 1 aborted /li/track request.

45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-506
SourceAI SANDBOX

DNR rules block LinkedIn telemetry and bot-detection endpoints

Taplio X installs 13 declarativeNetRequest rules blocking LinkedIn's bot-detection, CSP reporting, and telemetry endpoints.

Dynamic analysis captured 5 blocked POSTs to /platform-telemetry/apfcDf and 1 aborted /li/track request.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You install Taplio X and navigate to any LinkedIn page.

No additional interaction is required, the rules activate automatically on extension install.

The extension did this

13 declarativeNetRequest rules begin blocking LinkedIn's telemetry, bot-detection, and CSP reporting endpoints.

Requests to sensorCollect, platform-telemetry, contentsecurity, csp, and platform.linkedin.com are dropped before they reach LinkedIn's servers.

02EvidenceCODE COMPARE
The code that does this

rules.json, all 13 declarativeNetRequest block rules

What it actually does
Annotated: which endpoints serve which security functionsrules.json (annotated)
// sensorCollect (rules 3,4,9) — LinkedIn bot-detection behavioral sensor
// platform-telemetry (rules 1,2) — LinkedIn telemetry + CSP violation reporting
// lite/contentsecurity (rules 5,6) — Content Security Policy reporting endpoint
// uas/js/TXbEYyrcV7m5DbGr (rule 7) — LinkedIn user-agent / activity tracking script
// sc/h/br (rule 8) — LinkedIn Beacon reporting
// litms/api/metadata/user (rule 10) — LinkedIn session metadata endpoint
// platform.linkedin.com (rule 11) — LinkedIn platform API (embeds, widgets)
// sb.scorecardresearch.com (rule 12) — Third-party comScore audience measurement
// csp (rule 13) — CSP violation report-uri endpoint
//
// 11 of 13 rules target LinkedIn's security and monitoring infrastructure.
03EvidenceNETWORK CAPTURE
Captured request
POSThttps://www.linkedin.com/platform-telemetry/li/apfcDf
ERR_BLOCKED_BY_CLIENT, request dropped by declarativeNetRequest rule 1 before reaching LinkedIn's servers. Observed 5 times during dynamic analysis session.
04EvidenceARTIFACT
Check if you're affected

Reads the extension's rules.json and reports which LinkedIn security endpoints are blocked. Run against the extracted extension directory to confirm the ruleset.

RequiresNode.js 14+
taplio-x-dnr-audit.js · js
const fs = require('fs');
const path = require('path');

// Point this at the extracted extension directory
const rulesPath = process.argv[2] || path.join(__dirname, 'rules.json');
const rules = JSON.parse(fs.readFileSync(rulesPath, 'utf8'));

const SECURITY_CATEGORIES = [
  { pattern: 'platform-telemetry', label: 'LinkedIn telemetry / CSP violation reporting' },
  { pattern: 'sensorCollect',      label: 'LinkedIn bot-detection sensor' },
  { pattern: 'contentsecurity',    label: 'LinkedIn CSP reporting endpoint' },
  { pattern: 'uas/js',             label: 'LinkedIn user-activity tracking script' },
  { pattern: 'sc/h/br',            label: 'LinkedIn Beacon reporting' },
  { pattern: 'litms/api/metadata', label: 'LinkedIn session metadata API' },
  { pattern: 'platform.linkedin.com', label: 'LinkedIn platform embed API' },
  { pattern: 'scorecardresearch',  label: 'comScore third-party audience measurement' },
  { pattern: 'csp/',               label: 'LinkedIn CSP report-uri endpoint' },
];

const blockRules = rules.filter(r => r.action && r.action.type === 'block');
console.log(`Total block rules: ${blockRules.length}`);
console.log('');

SECURITY_CATEGORIES.forEach(({ pattern, label }) => {
  const matching = blockRules.filter(r => r.condition.urlFilter.includes(pattern));
  if (matching.length) {
    console.log(`[BLOCKED] ${label}`);
    matching.forEach(r => console.log(`  Rule ${r.id}: ${r.condition.urlFilter}`));
  }
});

const secCount = blockRules.filter(r =>
  SECURITY_CATEGORIES.some(c => r.condition.urlFilter.includes(c.pattern))
).length;
console.log(`\n${secCount} of ${blockRules.length} rules target LinkedIn security/monitoring infrastructure.`);
How to run it
  1. 1
    Extract the extension CRX (e.g. unzip extension.crx extracted/).
  2. 2
    Run: node taplio-x-dnr-audit.js path/to/extracted/rules.json.
  3. 3
    Review the BLOCKED lines, each is a LinkedIn security endpoint suppressed on your account.
Updated 21 September 2026dfpbcakpogbfaohnnjlgghdjkgaoiaik