Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Veltora CRM Platform

fkcifkeeglocoaekandppmecohhhjjld
Risk Score
5.38
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs
Rating
Last updated 2026-08-25
Manifest version MV3
CSP present ❌ no
Developer veltoracrmplatform@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Gmail developer with no business identity; free-webmail floor applies (reputation pillar 7.5).
  • Privacy policy is Google's own policy — not scoped to this extension; admits data collection and 3rd-party sharing (Privacy pillar 10).
  • Content script on web.whatsapp.com with cookies permission: can silently read all WhatsApp messages and session cookies.
  • No CSP declared (MV3 default applies) but js_external_hosts include notiflix.github.io and reactjs.org — remote JS dependency risk.
  • DOM-XSS sinks (innerHTML) in contentScript, app.js, background.js combined with function_constructor and no CSP elevates code quality risk.

Evidence

  • free_webmail_developer store Developer email veltoracrmplatform@gmail.com — free webmail, no business domain; reputation floor 7.5.
  • generic_privacy_policy store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → Privacy pillar 10.0.
  • cookies_on_whatsapp manifest cookies permission + host_permission https://web.whatsapp.com/* allows full WhatsApp session and message access.
  • external_js_hosts crx js_external_hosts: notiflix.github.io, reactjs.org — runtime dependency on third-party CDN domains.
  • dom_xss_no_csp crx innerHTML sinks in contentScript.js, app.js, background.js with csp_present=false → elevated DOM-XSS risk.
  • function_constructor crx new Function() in app.js is a dynamic code execution sink, risk amplified by no CSP.
  • licensing_server_host manifest host_permission https://app.coderlicences.com/* — unknown third-party licensing endpoint receives extension data.
  • no_installs_no_rating store Install count blank, rating 0 — unknown blast radius but new/obscure extension with high-capability permissions.

Permissions Breakdown

  • storage low Standard local data persistence for CRM state.
  • unlimitedStorage low Allows large local storage; low direct risk but enables large data caching.
  • tabs medium Can enumerate open tabs; risk depends on how data is used.
  • cookies high Cookie access on whatsapp.com enables session hijack risk.
  • notifications low Push notifications; moderate abuse potential for spam.
  • declarativeNetRequest medium Can modify/block network requests; scoped but impactful.
  • https://web.whatsapp.com/* high Full access to WhatsApp Web — can read all messages and session data.
  • https://app.coderlicences.com/* medium Access to external licensing server; unknown data flows.

Pillar Scores

Permissions5.00
Reputation7.50
Network4.50
Webstore2.50
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 11:27
Listing SHA 6a3cb06184de…
Force block — not fired
Score recovered no
Elapsed