Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

WA Sender - Bulk Messages & Automation

cgipcgghboamefelooajpiabilddemlh
Risk Score
5.29
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category PrivacyTool
Installs 200,000
Rating 4.4
Last updated 2026-08-26 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer luteyguillory8j3@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE-2021-23358 (ACE) in bundled underscore@1.8.3 — not patched to fixed_in 1.12.1.
  • Privacy policy is the Chrome Web Store listing page itself — no extension-scoped data handling disclosure.
  • Free-webmail developer (gmail) with no business identity impersonates WhatsApp brand.
  • bit.ly affiliate/cloaking hit in js_external_hosts — short-link redirector with opaque destination.
  • new Function() constructor present in both background.js and injected content script; no CSP to mitigate.

Evidence

  • critical_cve_bundled_lib crx underscore@1.8.3 carries CVE-2021-23358 (ACE, critical) and CVE-2026-27601 (high DoS); fixed versions available.
  • privacy_policy_is_store_listing store privacy_policy_url points to own Chrome Web Store listing page; no scoped policy; scope_extension=false, third_party_sharing=true.
  • brand_impersonation store brand_mention.is_impersonation=true for 'whatsapp'; confirmed_owner=false; developer domain is gmail.com.
  • free_webmail_dev_no_business store developer_email=luteyguillory8j3@gmail.com; no developer_name; no business domain.
  • affiliate_hit_bit_ly crx bit.ly in js_external_hosts — generic short-link redirector flagged as affiliate/cloaking by threat_intel.
  • function_constructor_no_csp crx new Function() in background.js and inject-script.js; csp_present=false; no MV3 override mitigation visible.
  • uninstall_url_hijack crx uninstall_url_hijack=true; extension registers an uninstall URL (target not resolved).
  • high_external_host_count crx 12 distinct js_external_hosts including waplus.io, watools.ai, feross.org beyond core whatsapp.com.

CVE Exposures (9)

CVELibrarySeverity Fixed inSummary
CVE-2021-23337 lodash@unknown high 4.17.21 Command Injection in lodash
CVE-2026-4800 lodash@unknown high 4.17.21 Command Injection in lodash
CVE-2018-16487 lodash@unknown high 4.17.11 Prototype Pollution in lodash
CVE-2025-13465 lodash@unknown moderate 4.18.0 lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and
CVE-2026-2950 lodash@unknown moderate 4.18.0 lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and
CVE-2018-3721 lodash@unknown moderate 4.17.5 Prototype Pollution in lodash
CVE-2019-10744 lodash@unknown critical 4.17.12 Prototype Pollution in lodash
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • storage low Stores extension settings locally; minimal risk.
  • alarms low Schedules periodic tasks; low abuse potential.
  • *://*.whatsapp.com/* (host) medium Content script on WhatsApp only; scoped but reads chat page DOM.

Pillar Scores

Permissions2.30
Reputation7.50
Network3.50
Webstore6.50
Maintenance0.00
Privacy10.00
Code Quality3.50
CVE Exposure7.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:23
Listing SHA 440ac9c422f8…
Force block — not fired
Score recovered no
Elapsed 27.5s