Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

WA Envio

dfcngbjlmlakepppfaaepideejcbfcjf
Risk Score
5.53
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 443
Rating 4.7
Last updated 2026-08-26
Manifest version MV3
CSP present ❌ no
Developer contato@extensao.store
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall URL hijack + install URL hijack detected — classic monetization/tracking shell pattern.
  • Privacy policy is Google's own policy (generic, unscoped) but admits data collection and 3rd-party sharing — Privacy pillar scores 10.
  • WhatsApp brand impersonation by unverified developer 'wty' via extensao.store domain.
  • 10 external JS hosts under wascript.com.br/watools.com.br contacted at runtime — large unverified backend surface.
  • function_constructor (new Function) combined with no CSP and innerHTML DOM-XSS sink raises code quality risk.

Evidence

  • install_url_hijack + uninstall_url_hijack crx Both onInstalled and uninstall URL hooks present; install redirects to https://web.whatsapp.com — monetization/tracking pattern.
  • generic_privacy_policy store Policy URL is Google's own privacy page; scope_extension=false, data_collection=true, third_party_sharing=true — Privacy pillar=10.
  • brand_impersonation store WhatsApp brand mentioned; developer not confirmed owner of brand; is_impersonation=true, not verified/featured.
  • large_external_host_surface crx 10 distinct wascript.com.br/watools.com.br endpoints in js_external_hosts — broad unverified backend.
  • function_constructor crx new Function() constructor found in bundled JS; no CSP present (MV3 but csp_present=false).
  • dom_sink_innerhtml_userctrl crx innerHTML assigned from variable; no CSP and eval-like finding present → elevated DOM-XSS risk (FIX B applies).
  • unverified_developer store Developer name 'wty', email contato@extensao.store; no verified publisher badge, no Google featured badge.
  • no_csp manifest content_security_policy is null; csp_present=false on MV3 extension with external hosts and code findings.

Permissions Breakdown

  • unlimitedStorage low Allows large local data storage; low direct harm but could cache sensitive data.
  • storage low Standard key-value local storage; low risk.
  • alarms low Schedule periodic tasks; low risk standalone.
  • tabs medium Can read tab URLs and titles; moderate risk for browsing history exposure.
  • https://web.whatsapp.com/* medium Host permission scoped to WhatsApp Web; allows content script injection and data access on that domain.

Pillar Scores

Permissions2.30
Reputation6.50
Network3.50
Webstore8.50
Maintenance0.00
Privacy10.00
Code Quality4.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 09:48
Listing SHA 76d202a1bb56…
Force block — not fired
Score recovered no
Elapsed