Is taplio x safe?
Taplio X is medium risk. Taplio X installs 13 declarativeNetRequest rules blocking LinkedIn's bot-detection, CSP reporting, and telemetry endpoints. Dynamic analysis captured 5 blocked POSTs to /platform-telemetry/apfcDf and 1 aborted /li/track request.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
DNR rules block LinkedIn telemetry and bot-detection endpoints
Taplio X installs 13 declarativeNetRequest rules blocking LinkedIn's bot-detection, CSP reporting, and telemetry endpoints.
Dynamic analysis captured 5 blocked POSTs to /platform-telemetry/apfcDf and 1 aborted /li/track request.
You install Taplio X and navigate to any LinkedIn page.
No additional interaction is required, the rules activate automatically on extension install.
13 declarativeNetRequest rules begin blocking LinkedIn's telemetry, bot-detection, and CSP reporting endpoints.
Requests to sensorCollect, platform-telemetry, contentsecurity, csp, and platform.linkedin.com are dropped before they reach LinkedIn's servers.
rules.json, all 13 declarativeNetRequest block rules
// sensorCollect (rules 3,4,9) — LinkedIn bot-detection behavioral sensor // platform-telemetry (rules 1,2) — LinkedIn telemetry + CSP violation reporting // lite/contentsecurity (rules 5,6) — Content Security Policy reporting endpoint // uas/js/TXbEYyrcV7m5DbGr (rule 7) — LinkedIn user-agent / activity tracking script // sc/h/br (rule 8) — LinkedIn Beacon reporting // litms/api/metadata/user (rule 10) — LinkedIn session metadata endpoint // platform.linkedin.com (rule 11) — LinkedIn platform API (embeds, widgets) // sb.scorecardresearch.com (rule 12) — Third-party comScore audience measurement // csp (rule 13) — CSP violation report-uri endpoint // // 11 of 13 rules target LinkedIn's security and monitoring infrastructure.
Reads the extension's rules.json and reports which LinkedIn security endpoints are blocked. Run against the extracted extension directory to confirm the ruleset.
const fs = require('fs');
const path = require('path');
// Point this at the extracted extension directory
const rulesPath = process.argv[2] || path.join(__dirname, 'rules.json');
const rules = JSON.parse(fs.readFileSync(rulesPath, 'utf8'));
const SECURITY_CATEGORIES = [
{ pattern: 'platform-telemetry', label: 'LinkedIn telemetry / CSP violation reporting' },
{ pattern: 'sensorCollect', label: 'LinkedIn bot-detection sensor' },
{ pattern: 'contentsecurity', label: 'LinkedIn CSP reporting endpoint' },
{ pattern: 'uas/js', label: 'LinkedIn user-activity tracking script' },
{ pattern: 'sc/h/br', label: 'LinkedIn Beacon reporting' },
{ pattern: 'litms/api/metadata', label: 'LinkedIn session metadata API' },
{ pattern: 'platform.linkedin.com', label: 'LinkedIn platform embed API' },
{ pattern: 'scorecardresearch', label: 'comScore third-party audience measurement' },
{ pattern: 'csp/', label: 'LinkedIn CSP report-uri endpoint' },
];
const blockRules = rules.filter(r => r.action && r.action.type === 'block');
console.log(`Total block rules: ${blockRules.length}`);
console.log('');
SECURITY_CATEGORIES.forEach(({ pattern, label }) => {
const matching = blockRules.filter(r => r.condition.urlFilter.includes(pattern));
if (matching.length) {
console.log(`[BLOCKED] ${label}`);
matching.forEach(r => console.log(` Rule ${r.id}: ${r.condition.urlFilter}`));
}
});
const secCount = blockRules.filter(r =>
SECURITY_CATEGORIES.some(c => r.condition.urlFilter.includes(c.pattern))
).length;
console.log(`\n${secCount} of ${blockRules.length} rules target LinkedIn security/monitoring infrastructure.`);- 1Extract the extension CRX (e.g. unzip extension.crx extracted/).
- 2Run: node taplio-x-dnr-audit.js path/to/extracted/rules.json.
- 3Review the BLOCKED lines, each is a LinkedIn security endpoint suppressed on your account.