Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

BulkifyWA

agjeofhaaekfnaalgjihiolgfmekhbhd
Risk Score
4.70
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 5
Rating
Last updated 2025-05-17 (15 months ago)
Manifest version MV3
CSP present ❌ no
Developer harikabhaskaram31@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Generic freeprivacypolicy.com policy not scoped to this extension; admits data collection and 3rd-party sharing → Privacy pillar 10.0.
  • WhatsApp brand impersonation by unverified gmail developer with no confirmed ownership.
  • Extension stale 15 months; no verified publisher, no featured badge.
  • dom_sink_innerhtml_userctrl in overlay.js without CSP; DOM-XSS risk on WhatsApp session.
  • External JS host sheetjs.com loaded from content running inside WhatsApp Web session.

Evidence

  • privacy_policy_generic store freeprivacypolicy.com template; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy (rule D).
  • brand_impersonation store brand_mention.is_impersonation=true for 'whatsapp'; developer is gmail user, confirmed_owner=false → +2.0 Reputation.
  • free_webmail_developer store Developer email harikabhaskaram31@gmail.com; no business domain; dev name matches email prefix → +1.5 Reputation.
  • dom_xss_sink_no_csp crx innerHTML sink in overlay.js; csp_present=false → +2.0 Code Quality (FIX B).
  • external_js_host_sheetjs crx js_external_hosts includes sheetjs.com; extension loads external JS inside WhatsApp Web context.
  • maintenance_stale store months_since_update=15; falls in 12-24mo band → +6.0 Maintenance.
  • no_verified_publisher store verified_publisher=false, is_featured_by_google=false; 5 installs, 0 ratings.
  • wayback_no_data api wayback_ownership fetch_error; no ownership-change signal available.

Permissions Breakdown

  • scripting medium Can inject JS into allowed hosts; scoped to web.whatsapp.com only.
  • host: https://web.whatsapp.com/* medium Narrow host scope to WhatsApp Web; fits stated bulk-messaging function.

Pillar Scores

Permissions2.30
Reputation7.00
Network0.00
Webstore2.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 04:56
Listing SHA 8178410e0389…
Force block — not fired
Score recovered no
Elapsed