Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Power Leads CRM

gajfjnadaloamfboafdfiopmfcdchkcf
Risk Score
5.45
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 40
Rating 5.0
Last updated 2026-01-12 (8 months ago)
Manifest version MV3
CSP present ❌ no
Developer suportepowerleadscrm@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's own generic policy — does not scope to this extension; data handling completely undisclosed.
  • cookies permission on WhatsApp Web allows session token access; combined with content script injection is high-impact.
  • No CSP defined (MV3 default); three innerHTML sinks across app.js, background.js, contentScript.js elevate DOM-XSS risk.
  • Gmail developer account, no developer name, no verified publisher — accountability is near-zero.
  • Small-install + high-perm anomaly (40 installs, cookies + tabs + host access) — tail-attack-surface red flag.

Evidence

  • free_webmail_dev_no_name store Developer email suportepowerleadscrm@gmail.com, no developer name listed; reputation floor applies.
  • generic_privacy_policy store Privacy URL points to myaccount.google.com/privacypolicy — Google's own policy, scope_extension=false, data_collection=true, third_party_sharing=true.
  • cookies_on_whatsapp manifest cookies permission + content_scripts on web.whatsapp.com/* enables session cookie read of WhatsApp accounts.
  • no_csp manifest content_security_policy is null; csp_present=false on MV3 extension with DOM-XSS sinks.
  • dom_xss_sinks crx dom_sink_innerhtml_userctrl found in app.js, background.js, contentScript.js; no CSP mitigates these.
  • install_perm_anomaly api 40 installs with cookies, tabs, declarativeNetRequest, and WhatsApp host access — small_install_high_perm=true.
  • external_js_hosts crx js_external_hosts reference notiflix.github.io and reactjs.org — third-party JS dependency chain without CSP control.
  • maintenance_6_12mo store months_since_update=8; falls in 6-12 month band, +3.5 maintenance score.

Permissions Breakdown

  • storage low Local data persistence; low risk alone.
  • unlimitedStorage low Extends storage quota; minimal risk.
  • tabs medium Can read tab URLs and titles; moderate privacy risk.
  • cookies high Can read/write cookies; scoped to whatsapp.com and coderlicences.com but still sensitive.
  • notifications low Can display browser notifications; low standalone risk.
  • declarativeNetRequest medium Can modify network requests declaratively; moderate capability.
  • https://web.whatsapp.com/* high Full DOM and cookie access to WhatsApp Web; high privacy impact.
  • https://app.coderlicences.com/* medium Access to third-party licensing server; potential data exfil surface.

Pillar Scores

Permissions5.50
Reputation7.50
Network3.50
Webstore4.00
Maintenance3.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 05:37
Listing SHA 6046a0ae4786…
Force block — not fired
Score recovered no
Elapsed