Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

WhatsVoice

ccnllpcenlhbhnkbofajkdlabadcglcd
Risk Score
5.07
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 62
Rating 4.7
Last updated 2026-08-24 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer mkt.robenilson@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy URL failed to fetch — policy unverifiable, treated as absent (score +10.0).
  • Brand impersonation: uses 'whatsapp' brand name with no confirmed ownership, developer on gmail.
  • function_constructor (new Function) in bundled JS enables arbitrary code execution paths.
  • DOM-XSS sink via innerHTML without CSP to mitigate, amplifying code-quality risk.
  • Gmail developer with no verified business identity, no publisher verification, no featured badge.

Evidence

  • privacy_policy_fetch_failed api Policy URL https://vmsender.com/privacy-policy.html returned HTTPError; treated as fetched==false → +10.0 privacy.
  • brand_impersonation store brand_mention.is_impersonation=true for 'whatsapp'; developer domain is gmail.com, confirmed_owner=false.
  • free_webmail_developer store Developer email mkt.robenilson@gmail.com is free webmail; no business website verified.
  • function_constructor crx new Function() constructor in whatsvoice_193.js — can execute dynamically constructed code strings.
  • dom_sink_innerhtml_userctrl crx innerHTML sink in whatsvoice_12.js; csp_present=false amplifies XSS risk (+2.0 code quality).
  • no_csp manifest content_security_policy is null (MV3 strict default applies, no explicit CSP declared).
  • js_external_hosts crx 12 distinct external JS hosts including generativelanguage.googleapis.com, socket.io, github.com.
  • low_install_count store Only 62 installs; low adoption with no verified publisher increases tail-attack-surface concern.

Permissions Breakdown

  • unlimitedStorage low Allows unrestricted local storage; low direct risk but could accumulate data.
  • storage low Standard local key-value storage, low risk.
  • alarms low Scheduled background execution, low risk alone.
  • tabs medium Access to tab URLs and metadata across browser sessions.
  • https://web.whatsapp.com/* medium Host access scoped to WhatsApp Web; can read/inject into all WhatsApp sessions.

Pillar Scores

Permissions2.30
Reputation7.50
Network2.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 15:48
Listing SHA 1b37bac8258e…
Force block — not fired
Score recovered no
Elapsed