Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

WhatSender PRO - WhatsApp Bulk Sender

cpficbpjnbekidkijhpbofgncpfolmeb
Risk Score
4.43
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 1,000
Rating 4.9
Last updated 2026-08-24
Manifest version MV3
CSP present ❌ no
Developer tuttoemailsoft@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and third-party sharing.
  • Brand impersonation: extension uses 'WhatsApp' brand name; developer is unverified gmail user with no confirmed ownership.
  • Bundled jQuery 3.4.1 has two medium-severity XSS CVEs (CVE-2020-11022, CVE-2020-11023); no CSP to mitigate.
  • DOM-XSS sink (innerHTML) in content.js combined with no CSP and vulnerable jQuery amplifies XSS risk on WhatsApp domain.
  • Free-webmail developer (tuttoemailsoft@gmail.com), no developer name, no verified publisher — minimal accountability.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; developer gmail.com not confirmed WhatsApp owner.
  • generic_privacy_policy store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • cve_jquery_xss crx jQuery 3.4.1 bundled; CVE-2020-11022 and CVE-2020-11023 (medium severity); fixed_in 3.5.0.
  • dom_sink_no_csp crx innerHTML sink in content.js with csp_present=false and vulnerable jQuery; elevated XSS risk.
  • free_webmail_dev_no_name store Developer email tuttoemailsoft@gmail.com; developer_name empty; no verified publisher badge.
  • install_url_hijack manifest install_url_hijack=true; onInstalled opens https://web.whatsapp.com (same domain as stated function).
  • privacy_policy_d_clause store scope_extension=false AND data_collection=true AND third_party_sharing=true → Privacy pillar +10.0 (v3.5 D).
  • cve_amplifier_no_csp_jquery crx No CSP + DOM-manipulation lib with medium CVEs triggers v2 ×1.5 CVE amplifier; cve_pillar=4.5.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2020-11022 jquery@3.4.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.4.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • tabs medium Can read tab URLs/titles; moderate risk for session awareness.
  • storage low Local extension data storage; low standalone risk.
  • activeTab low Scoped to user-clicked tab only; low risk.
  • sidePanel low UI panel display; no data-access risk.
  • *://*.whatsapp.com/* medium Content-script and host access scoped to WhatsApp only; matches stated function.

Pillar Scores

Permissions2.30
Reputation8.50
Network0.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality2.50
CVE Exposure4.50

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 04:48
Listing SHA eae81d728e69…
Force block — not fired
Score recovered no
Elapsed