Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Zap4Biz: Automação, CRM e Chatbot para WhatsApp Web

gjnkcmipmfefifmlabnljnpcikmngooo
Risk Score
3.55
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Productivity
Installs 19
Rating
Last updated 2026-04-27 (5 months ago)
Manifest version MV3
CSP present ❌ no
Developer wl.exten.02@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Free-webmail Gmail developer with no verified identity — typical throwaway account pattern.
  • WhatsApp brand impersonation: developer is not affiliated with Meta/WhatsApp.
  • Content script on web.whatsapp.com can read messages; no host_permissions but scoped injection.
  • install_url_hijack opens web.whatsapp.com on install — low-severity redirect anomaly.
  • DOM-XSS innerHTML sink in vendor bundle with no CSP — elevated XSS risk on WhatsApp Web.

Evidence

  • free_webmail_dev store Developer email wl.exten.02@gmail.com — numbered alias Gmail, no business domain.
  • brand_impersonation store brand_mention.is_impersonation=true for 'whatsapp'; developer not confirmed owner.
  • install_url_hijack manifest install_url_hijack=true; onInstalled opens https://web.whatsapp.com (benign target but anomalous).
  • dom_xss_sink_no_csp crx innerHTML sink in vendor.DzFEYc3-.js; csp_present=false — DOM-XSS risk on WhatsApp origin.
  • whatsapp_content_script manifest Content script injected into https://web.whatsapp.com/* — can access message DOM.
  • external_host_hiperchat crx JS external host hc-stt.hiperchat.com.br — unknown BR domain, possible STT/data relay.
  • privacy_policy_third_party api Policy discloses third_party_sharing=true; hosted on opt-api.com not dev-controlled domain.
  • very_low_installs store Only 19 installs — very early/experimental; limited blast radius currently.

Permissions Breakdown

  • unlimitedStorage low Allows unbounded local storage; low direct harm but can accumulate data.
  • storage low Standard key-value storage for extension state.
  • tabs medium Can read tab URLs/titles across sessions; moderate surveillance surface.
  • alarms low Schedules background tasks; low risk alone.
  • content_scripts:https://web.whatsapp.com/* medium Injects JS into WhatsApp Web — can read messages and UI state.

Pillar Scores

Permissions2.30
Reputation7.50
Network1.50
Webstore4.50
Maintenance1.50
Privacy1.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 16:10
Listing SHA 9651ab396792…
Force block — not fired
Score recovered no
Elapsed