Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

ChatzyCRM: Todo lo que necesitas en un solo CRM para WhatsApp

bpjhhjboiagpamldnmjdmjadhajipicf
Risk Score
5.38
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 5
Rating
Last updated 2025-09-14 (11 months ago)
Manifest version MV3
CSP present ❌ no
Developer scanazas@nexcorp.pe
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Content script injected into WhatsApp Web can read all messages and user data with no CSP protection.
  • Privacy policy is Google's generic policy — does not scope to this extension; admits data collection and third-party sharing (D rule: +10).
  • WhatsApp brand impersonation by unverified developer (nexcorp.pe).
  • Uninstall URL hijack and install URL hijack both present — monetization/tracking shell signals.
  • 12 distinct external JS hosts including multiple wascript.com.br and watidy.com domains with no CSP.

Evidence

  • content_script_whatsapp manifest Content script on https://web.whatsapp.com/* with no CSP — full DOM/message access.
  • privacy_policy_generic_google store Privacy URL is myaccount.google.com/privacypolicy — Google's own policy, not scoped to this extension.
  • brand_impersonation_whatsapp store brand_mention.is_impersonation=true; developer nexcorp.pe is not confirmed WhatsApp owner.
  • url_hijack_both crx uninstall_url_hijack=true AND install_url_hijack=true; install target https://web.whatsapp.com.
  • external_hosts_count crx 12 js_external_hosts including wascript.com.br (x4), watidy.com, wabacrm.store, glexmedia.in.
  • no_csp manifest content_security_policy is null/absent on MV3 extension with remote host dependencies.
  • function_constructor crx new Function() constructor found in bundled JS — dynamic code execution risk.
  • privacy_policy_admits_third_party api policy: scope_extension=false, data_collection=true, third_party_sharing=true — triggers D rule max score.

Permissions Breakdown

  • unlimitedStorage low Allows unlimited local storage; low direct harm.
  • storage low Standard local key-value storage access.
  • alarms low Scheduling API; low risk on its own.
  • tabs medium Can read tab URLs and metadata across all tabs.
  • declarativeNetRequest medium Can redirect/block network requests declaratively.
  • *://*.glexmedia.in/* medium Host access to third-party domain of unclear ownership.
  • *://*.wabacrm.store/* medium Host access to developer-adjacent CRM backend domain.
  • *://chatzycrm.com/* medium Host access to extension's own backend domain.
  • content_scripts: https://web.whatsapp.com/* high Injects JS into WhatsApp Web; can read all messages and DOM.

Pillar Scores

Permissions2.60
Reputation6.50
Network4.00
Webstore7.50
Maintenance3.50
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 08:04
Listing SHA 17755e93db82…
Force block — not fired
Score recovered no
Elapsed