Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

MagisAtende

glcnfenofhiojbncadgjocladkdeacep
Risk Score
3.69
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Productivity
Installs 12
Rating 5.0
Last updated 2026-06-16 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer dennerverli@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Free-webmail developer email (gmail) with no verified publisher status raises accountability concerns.
  • Brand mention of WhatsApp with unconfirmed ownership flagged as impersonation by brand_mention check.
  • Privacy policy fetched but lacks extension-scope disclosure and data collection details — scores maximum privacy risk.
  • DOM-XSS sink (innerHTML) in content script on WhatsApp Web without CSP protection.
  • No CSP declared on MV3 extension; amplifies DOM-sink risk on WhatsApp Web content script.

Evidence

  • free_webmail_developer store Developer email dennerverli@gmail.com is free webmail; no verified publisher badge.
  • brand_impersonation store brand_mention.is_impersonation=true; WhatsApp mentioned, developer domain is gmail.com, not Meta.
  • privacy_policy_inadequate api Policy fetched but scope_extension=false, data_collection=false, third_party_silence=true; no extension-specific disclosure.
  • dom_xss_sink crx dom_sink_innerhtml_userctrl in assets/content.js; no CSP to mitigate.
  • no_csp manifest content_security_policy is null; csp_present=false on MV3 extension with DOM sink.
  • reactjs_external_host crx js_external_hosts includes reactjs.org; external JS reference beyond dev-controlled domain.
  • tiny_install_base store Only 12 installs; limited blast radius but also no community scrutiny.
  • no_bad_hosts_or_cves api bad_host_hits=[], cve_findings_raw=[], monetization_hits=[], affiliate_hits=[] — no threat intel hits.

Permissions Breakdown

  • storage low Stores local extension data; minimal risk.
  • alarms low Schedules background tasks; no data access.
  • identity low OAuth token access; scopes not declared, moderate risk in context.
  • *://web.whatsapp.com/* medium Scoped host access to WhatsApp Web; matches stated CRM function.
  • https://apimagisatende.magisia.com.br/* low Dev-controlled API endpoint; narrow scope.

Pillar Scores

Permissions1.60
Reputation7.00
Network0.00
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 04:47
Listing SHA 684f57f8f1df…
Force block — not fired
Score recovered no
Elapsed