Power Leads CRM
gajfjnadaloamfboafdfiopmfcdchkcf
Risk Score
5.45
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's own generic policy — does not scope to this extension; data handling completely undisclosed.
- cookies permission on WhatsApp Web allows session token access; combined with content script injection is high-impact.
- No CSP defined (MV3 default); three innerHTML sinks across app.js, background.js, contentScript.js elevate DOM-XSS risk.
- Gmail developer account, no developer name, no verified publisher — accountability is near-zero.
- Small-install + high-perm anomaly (40 installs, cookies + tabs + host access) — tail-attack-surface red flag.
Evidence
- free_webmail_dev_no_name store Developer email suportepowerleadscrm@gmail.com, no developer name listed; reputation floor applies.
- generic_privacy_policy store Privacy URL points to myaccount.google.com/privacypolicy — Google's own policy, scope_extension=false, data_collection=true, third_party_sharing=true.
- cookies_on_whatsapp manifest cookies permission + content_scripts on web.whatsapp.com/* enables session cookie read of WhatsApp accounts.
- no_csp manifest content_security_policy is null; csp_present=false on MV3 extension with DOM-XSS sinks.
- dom_xss_sinks crx dom_sink_innerhtml_userctrl found in app.js, background.js, contentScript.js; no CSP mitigates these.
- install_perm_anomaly api 40 installs with cookies, tabs, declarativeNetRequest, and WhatsApp host access — small_install_high_perm=true.
- external_js_hosts crx js_external_hosts reference notiflix.github.io and reactjs.org — third-party JS dependency chain without CSP control.
- maintenance_6_12mo store months_since_update=8; falls in 6-12 month band, +3.5 maintenance score.
Permissions Breakdown
- storage low Local data persistence; low risk alone.
- unlimitedStorage low Extends storage quota; minimal risk.
- tabs medium Can read tab URLs and titles; moderate privacy risk.
- cookies high Can read/write cookies; scoped to whatsapp.com and coderlicences.com but still sensitive.
- notifications low Can display browser notifications; low standalone risk.
- declarativeNetRequest medium Can modify network requests declaratively; moderate capability.
- https://web.whatsapp.com/* high Full DOM and cookie access to WhatsApp Web; high privacy impact.
- https://app.coderlicences.com/* medium Access to third-party licensing server; potential data exfil surface.
Pillar Scores
Permissions5.50
Reputation7.50
Network3.50
Webstore4.00
Maintenance3.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 05:37
Listing SHA
6046a0ae4786…
Force block
— not fired
Score recovered
no
Elapsed
—