Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

WaUp

eliddpopegfnapciabpclokjfedpnpij
Risk Score
4.47
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 82
Rating 5.0
Last updated 2025-11-26 (10 months ago)
Manifest version MV3
CSP present ❌ no
Developer hebrainmartins@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy URL is Google's generic policy (fetch error); no extension-specific data disclosure exists.
  • Free-webmail Gmail developer with no verified business identity; unaccountable if extension is sold.
  • eval() in bundled audio encoder libs with no CSP; remote-code-execution surface if libs are compromised.
  • External JS host 'discoveric.ru' (Russia-geolocated) alongside 3 distinct country origins raises supply-chain concern.
  • Content script on web.whatsapp.com can read message DOM; combined with third-party backend API (prontei.com), message data could be exfiltrated.

Evidence

  • free_webmail_developer store Developer email hebrainmartins@gmail.com — free webmail, no verified business domain.
  • privacy_policy_fetch_failed api Privacy policy URL points to Google's generic policy; fetch returned SSLError — no extension-scoped policy.
  • eval_in_bundled_libs crx eval() found in Mp3LameEncoder.min.js and OggVorbisEncoder.min.js; no CSP to mitigate.
  • function_constructor crx new Function() in sweetalert2.js can execute arbitrary strings; no CSP present.
  • suspicious_external_host crx JS contacts discoveric.ru (RU-geolocated); unrecognized host for a WhatsApp productivity tool.
  • third_party_backend manifest host_permission for app.prontei.com/api/* — data from WhatsApp DOM could be sent to unknown backend.
  • no_csp manifest content_security_policy is null; eval and Function() findings have no mitigating CSP barrier.
  • geo_diversity api JS hosts span 3 countries (CA, RU, US); Russian-hosted endpoint is anomalous for this category.

Permissions Breakdown

  • storage low Local data persistence; low harm potential alone.
  • unlimitedStorage low Extends storage quota; no direct data-exfil risk.
  • activeTab low Scoped to user-activated tab; limited reach.
  • host: https://web.whatsapp.com/* medium Content script on WhatsApp; can read messages and DOM.
  • host: https://app.prontei.com/api/* medium Allows XHR to third-party backend; data could be sent there.

Pillar Scores

Permissions1.00
Reputation7.50
Network3.50
Webstore2.50
Maintenance3.50
Privacy10.00
Code Quality3.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 16:23
Listing SHA 89860d4eed40…
Force block — not fired
Score recovered no
Elapsed