Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

GL MEDLEAD CRM

fcmjkjmkpgfhchcekjdgolldhnmacpfa
Risk Score
6.02
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category Productivity
Installs 207
Rating
Last updated 2026-08-25
Manifest version MV3
CSP present ❌ no
Developer gabrielmoreiramedico@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Google privacy policy used as extension policy — scoped to Google, not this extension; admits data collection and 3rd-party sharing.
  • Full content-script access to WhatsApp Web with cookies permission — can exfiltrate messages, contacts, and session tokens.
  • new Function() constructor in app.js enables dynamic code execution; no CSP to mitigate.
  • Multiple innerHTML DOM-XSS sinks across 3 files with no CSP present, raising XSS risk on WhatsApp context.
  • Free-webmail developer (gmail), no developer name, no verified publisher — low accountability.

Evidence

  • google_privacy_policy_misuse store Privacy URL is Google's own account policy — scope_extension=false, admits data collection and 3rd-party sharing; v3.5(D) triggers +10.0 privacy.
  • whatsapp_cookies_access manifest cookies permission + content_script on web.whatsapp.com enables session/message exfiltration.
  • function_constructor crx new Function() in app.js allows dynamic code execution; +2.5 code quality.
  • dom_xss_sinks_no_csp crx innerHTML in 3 files with csp_present=false triggers elevated +2.0 per FIX B each (capped).
  • free_webmail_no_devname store gabrielmoreiramedico@gmail.com, no developer_name — reputation floor 7.5 applied.
  • small_install_high_perm api 207 installs with cookies+tabs+whatsapp host — install_perm_anomaly.small_install_high_perm=true, +1.5 webstore.
  • external_js_hosts crx js_external_hosts: notiflix.github.io, reactjs.org — 2 external JS CDN hosts with no CSP.
  • no_csp_mv3 manifest csp_present=false on MV3; no v2 +2.0 penalty but amplifies code quality findings.

Permissions Breakdown

  • storage low Standard local data persistence, low risk.
  • unlimitedStorage low Allows large local storage; minor risk alone.
  • tabs medium Can read tab URLs and metadata across sessions.
  • cookies high Can read/write cookies; scoped to whatsapp.com and coderlicences.com.
  • notifications low Can display system notifications.
  • declarativeNetRequest medium Can block/redirect network requests declaratively.
  • https://web.whatsapp.com/* high Full script access to WhatsApp Web — messages, contacts, sessions.
  • https://app.coderlicences.com/* medium Access to developer-controlled licensing server; potential data exfil.

Pillar Scores

Permissions5.50
Reputation7.50
Network4.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-27 16:10
Listing SHA 4720d840dac4…
Force block — not fired
Score recovered no
Elapsed