GL MEDLEAD CRM
fcmjkjmkpgfhchcekjdgolldhnmacpfa
Risk Score
6.02
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- Google privacy policy used as extension policy — scoped to Google, not this extension; admits data collection and 3rd-party sharing.
- Full content-script access to WhatsApp Web with cookies permission — can exfiltrate messages, contacts, and session tokens.
- new Function() constructor in app.js enables dynamic code execution; no CSP to mitigate.
- Multiple innerHTML DOM-XSS sinks across 3 files with no CSP present, raising XSS risk on WhatsApp context.
- Free-webmail developer (gmail), no developer name, no verified publisher — low accountability.
Evidence
- google_privacy_policy_misuse store Privacy URL is Google's own account policy — scope_extension=false, admits data collection and 3rd-party sharing; v3.5(D) triggers +10.0 privacy.
- whatsapp_cookies_access manifest cookies permission + content_script on web.whatsapp.com enables session/message exfiltration.
- function_constructor crx new Function() in app.js allows dynamic code execution; +2.5 code quality.
- dom_xss_sinks_no_csp crx innerHTML in 3 files with csp_present=false triggers elevated +2.0 per FIX B each (capped).
- free_webmail_no_devname store gabrielmoreiramedico@gmail.com, no developer_name — reputation floor 7.5 applied.
- small_install_high_perm api 207 installs with cookies+tabs+whatsapp host — install_perm_anomaly.small_install_high_perm=true, +1.5 webstore.
- external_js_hosts crx js_external_hosts: notiflix.github.io, reactjs.org — 2 external JS CDN hosts with no CSP.
- no_csp_mv3 manifest csp_present=false on MV3; no v2 +2.0 penalty but amplifies code quality findings.
Permissions Breakdown
- storage low Standard local data persistence, low risk.
- unlimitedStorage low Allows large local storage; minor risk alone.
- tabs medium Can read tab URLs and metadata across sessions.
- cookies high Can read/write cookies; scoped to whatsapp.com and coderlicences.com.
- notifications low Can display system notifications.
- declarativeNetRequest medium Can block/redirect network requests declaratively.
- https://web.whatsapp.com/* high Full script access to WhatsApp Web — messages, contacts, sessions.
- https://app.coderlicences.com/* medium Access to developer-controlled licensing server; potential data exfil.
Pillar Scores
Permissions5.50
Reputation7.50
Network4.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-27 16:10
Listing SHA
4720d840dac4…
Force block
— not fired
Score recovered
no
Elapsed
—