TriadeFlux WEB ZAP
ehombimaojbcpfkkdhfioafllllnijdp
Risk Score
5.87
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's own policy — not scoped to this extension; admits data collection and third-party sharing.
- Cookies permission + WhatsApp Web host access: can exfiltrate session tokens and message data.
- No CSP + innerHTML sinks in 3 files + new Function() constructor: DOM-XSS and code-injection risk.
- Free-webmail developer (gmail), no developer name, no business identity — unverifiable accountability.
- Small-install + high-perm anomaly: 26 installs with cookies, tabs, declarativeNetRequest, and WhatsApp access.
Evidence
- privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 Privacy (v3.5-D).
- free_webmail_no_devname store triadeflux@gmail.com, developer_name empty, no business domain — Reputation floor triggered at 7.5.
- cookies_whatsapp_host manifest cookies permission + https://web.whatsapp.com/* host: can read WhatsApp session cookies and message content.
- no_csp_innerhtml_sink crx csp_present=false AND dom_sink_innerhtml_userctrl in 3 files — each triggers +2.0 under v3 FIX B.
- function_constructor crx new Function() in app.js — dynamic code execution risk (+2.5 code quality).
- external_js_hosts manifest js_external_hosts: notiflix.github.io, reactjs.org — MV3 + no CSP adds +2.0 network (v2 fix b).
- small_install_high_perm api install_perm_anomaly.small_install_high_perm=true: 26 installs with cookies, tabs, declarativeNetRequest.
- coderlicences_host manifest https://app.coderlicences.com/* host permission to unknown third-party licensing server raises supply-chain concern.
Permissions Breakdown
- storage low Stores local extension data; low risk.
- unlimitedStorage low Allows large local storage; low direct risk.
- tabs medium Can read tab URLs and metadata across sessions.
- cookies high Can read/write cookies; scoped to whatsapp.com and coderlicences.com host perms.
- notifications low Can display notifications; limited risk.
- declarativeNetRequest medium Can intercept/redirect network requests declaratively.
- https://web.whatsapp.com/* medium Full access to WhatsApp Web — can read messages and session data.
- https://app.coderlicences.com/* medium Access to unknown third-party licensing server; unclear purpose.
Pillar Scores
Permissions5.50
Reputation7.50
Network4.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 11:28
Listing SHA
0ff1f091bc21…
Force block
— not fired
Score recovered
no
Elapsed
—