Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

WaBest

ghajfmiecdhdkifpapbjngmcdbedjmgg
Risk Score
5.45
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 835
Rating 4.5
Last updated 2026-08-26
Manifest version MV3
CSP present ❌ no
Developer contato@extensao.store
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's own policy (not scoped to this extension) — admits data collection and 3rd-party sharing: scores +10.0.
  • Uninstall URL hijack and install URL hijack both flagged — aggressive lifecycle interception.
  • WhatsApp brand impersonation by unverified developer 'wty' on throwaway-pattern domain.
  • 10 external JS hosts (wascript.com.br, watools.com.br) contacted at runtime with no CSP — remote code loading surface.
  • function_constructor (new Function) in bundled JS combined with no CSP raises XSS/code-injection risk.

Evidence

  • privacy_policy_generic_google store Privacy URL points to Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • uninstall_and_install_url_hijack crx uninstall_url_hijack=true and install_url_hijack=true; install target=https://web.whatsapp.com — lifecycle interception +3.0+2.0 webstore.
  • brand_impersonation_whatsapp store brand_mention.is_impersonation=true, confirmed_owner=false, developer not verified → +2.0 reputation.
  • js_external_hosts_count crx 10 distinct external hosts under wascript.com.br/watools.com.br; >3 distinct registrable domains → +1.5 network.
  • no_csp_mv3 manifest csp_present=false on MV3; dom_sink_innerhtml_userctrl present → FIX B applies, dom_sink scored at +2.0 code quality.
  • function_constructor_finding crx new Function() constructor detected → +2.5 code quality (debugger_attach/function_constructor tier).
  • developer_identity_weak store Developer name 'wty' is opaque; email on extensao.store TLD; not verified publisher, not featured → reputation base elevated.
  • install_count_low_with_high_external_surface store Only 835 installs but 334 JS files and 10 external hosts — large attack surface relative to user base.

Permissions Breakdown

  • unlimitedStorage low Allows storing large data locally; low direct harm potential.
  • storage low Standard local key-value storage, minimal risk.
  • alarms low Scheduling alarms; low risk in isolation.
  • tabs medium Can read tab URLs and titles across sessions; moderate privacy risk.
  • https://web.whatsapp.com/* (host) medium Content script on WhatsApp Web; can read all chat data on that domain.

Pillar Scores

Permissions2.30
Reputation6.00
Network4.00
Webstore8.50
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 10:10
Listing SHA 32e5e00fe1c5…
Force block — not fired
Score recovered no
Elapsed