Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

WhatsApp Contacts Downloader — Free & Unlimited

fpeeookideimkcgcaodgekbgomnbkdkk
Risk Score
4.75
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 228
Rating 3.7
Last updated 2026-05-26 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer contact@quantana.com.au
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • WhatsApp brand impersonation by unverified third-party developer (Quantana/PaperPlanes).
  • Privacy policy admits data collection and 3rd-party sharing but is not scoped to this extension — score +10.
  • scripting + downloads on web.whatsapp.com allows contact data harvesting and silent file exfil.
  • Two additional developer-owned domains (paperplanes.rsvp, paperplanes.quantana.top) in host_permissions with unknown purpose.
  • No CSP on MV3 extension with external host access; no code findings to verify benign behavior.

Evidence

  • brand_impersonation store WhatsApp brand mentioned; developer domain quantana.com.au is not confirmed owner — is_impersonation=true.
  • privacy_policy_generic api Policy fetched (100 KB), scope_extension=false, data_collection=true, third_party_sharing=true — maps to +10 Privacy.
  • whatsapp_host_access manifest host_permissions includes https://web.whatsapp.com/* granting full read access to WhatsApp Web session.
  • extra_developer_domains manifest paperplanes.rsvp and paperplanes.quantana.top in host_permissions; purpose undisclosed in description.
  • no_csp manifest content_security_policy is null; csp_present=false on MV3 extension.
  • low_install_scraper store 228 installs; scraper targeting WhatsApp group member data (contacts CSV export).
  • downloads_permission manifest downloads permission enables writing arbitrary files to disk, potential data exfil vector.
  • unverified_developer store verified_publisher=false, is_featured_by_google=false; no badge to offset reputation risk.

Permissions Breakdown

  • scripting medium Can inject JS into whatsapp.com pages — captures contact data in DOM.
  • tabs medium Can read URLs/titles of open tabs.
  • storage low Local extension data storage; low standalone risk.
  • activeTab low Scoped to current tab on user gesture; limited exposure.
  • downloads medium Can write files to disk — used for CSV export but also for data exfil.
  • https://web.whatsapp.com/* high Full access to WhatsApp Web — can read all messages and contacts.
  • https://paperplanes.rsvp/* medium Developer-controlled secondary domain; unknown data flow.
  • https://paperplanes.quantana.top/* medium Developer-controlled subdomain; unknown data flow.

Pillar Scores

Permissions3.30
Reputation7.00
Network2.00
Webstore6.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 04:47
Listing SHA 08ae2503312b…
Force block — not fired
Score recovered no
Elapsed