Veltora CRM Platform
fkcifkeeglocoaekandppmecohhhjjld
Risk Score
5.38
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Gmail developer with no business identity; free-webmail floor applies (reputation pillar 7.5).
- Privacy policy is Google's own policy — not scoped to this extension; admits data collection and 3rd-party sharing (Privacy pillar 10).
- Content script on web.whatsapp.com with cookies permission: can silently read all WhatsApp messages and session cookies.
- No CSP declared (MV3 default applies) but js_external_hosts include notiflix.github.io and reactjs.org — remote JS dependency risk.
- DOM-XSS sinks (innerHTML) in contentScript, app.js, background.js combined with function_constructor and no CSP elevates code quality risk.
Evidence
- free_webmail_developer store Developer email veltoracrmplatform@gmail.com — free webmail, no business domain; reputation floor 7.5.
- generic_privacy_policy store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → Privacy pillar 10.0.
- cookies_on_whatsapp manifest cookies permission + host_permission https://web.whatsapp.com/* allows full WhatsApp session and message access.
- external_js_hosts crx js_external_hosts: notiflix.github.io, reactjs.org — runtime dependency on third-party CDN domains.
- dom_xss_no_csp crx innerHTML sinks in contentScript.js, app.js, background.js with csp_present=false → elevated DOM-XSS risk.
- function_constructor crx new Function() in app.js is a dynamic code execution sink, risk amplified by no CSP.
- licensing_server_host manifest host_permission https://app.coderlicences.com/* — unknown third-party licensing endpoint receives extension data.
- no_installs_no_rating store Install count blank, rating 0 — unknown blast radius but new/obscure extension with high-capability permissions.
Permissions Breakdown
- storage low Standard local data persistence for CRM state.
- unlimitedStorage low Allows large local storage; low direct risk but enables large data caching.
- tabs medium Can enumerate open tabs; risk depends on how data is used.
- cookies high Cookie access on whatsapp.com enables session hijack risk.
- notifications low Push notifications; moderate abuse potential for spam.
- declarativeNetRequest medium Can modify/block network requests; scoped but impactful.
- https://web.whatsapp.com/* high Full access to WhatsApp Web — can read all messages and session data.
- https://app.coderlicences.com/* medium Access to external licensing server; unknown data flows.
Pillar Scores
Permissions5.00
Reputation7.50
Network4.50
Webstore2.50
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 11:27
Listing SHA
6a3cb06184de…
Force block
— not fired
Score recovered
no
Elapsed
—