Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Whats Auto Send

dmehhcjdoejcpoffjpfnhfglcacofmdn
Risk Score
5.57
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 447
Rating
Last updated 2023-07-03 (37 months ago)
Manifest version MV3
CSP present ❌ no
Developer jusceirramos@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Completely abandoned: 37 months since last update, no maintenance signal.
  • Privacy policy is Google's generic policy — not scoped to this extension; admits data collection & 3rd-party sharing.
  • function_constructor (new Function) in login.js combined with no CSP raises code-execution risk.
  • Multiple innerHTML sinks across popup/options/login with no CSP to mitigate DOM-XSS.
  • Free-webmail developer (gmail.com), no verified publisher, no business domain — no accountability.

Evidence

  • maintenance_stale store Last updated July 2023; 37 months since update — zombie extension (>36mo threshold).
  • privacy_policy_generic store PP URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • code_function_constructor crx new Function() constructor in js/login.js with no CSP — dynamic code execution surface.
  • code_innerhtml_sinks crx innerHTML user-controlled sinks in popup.js, options.js, login.js; no CSP present.
  • developer_free_webmail store Developer email jusceirramos@gmail.com; no business domain; not verified publisher.
  • no_csp manifest content_security_policy is null; MV3 default applies but no explicit CSP tightens innerHTML risk.
  • content_script_whatsapp manifest Content script injected into https://web.whatsapp.com/* — access to message DOM.
  • no_rating store 0 ratings across 447 installs; no community accountability signal.

Permissions Breakdown

  • activeTab low Grants access only to the currently active tab on user gesture; narrow scope.
  • storage low Local extension storage only; no cross-origin data exfil surface.
  • content_scripts: https://web.whatsapp.com/* medium Injects scripts into WhatsApp Web; can read messages/DOM on that origin.

Pillar Scores

Permissions0.60
Reputation6.50
Network0.00
Webstore0.00
Maintenance10.00
Privacy10.00
Code Quality4.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 04:48
Listing SHA 75bbca589fdf…
Force block — not fired
Score recovered no
Elapsed