MagisAtende
glcnfenofhiojbncadgjocladkdeacep
Risk Score
3.69
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Free-webmail developer email (gmail) with no verified publisher status raises accountability concerns.
- Brand mention of WhatsApp with unconfirmed ownership flagged as impersonation by brand_mention check.
- Privacy policy fetched but lacks extension-scope disclosure and data collection details — scores maximum privacy risk.
- DOM-XSS sink (innerHTML) in content script on WhatsApp Web without CSP protection.
- No CSP declared on MV3 extension; amplifies DOM-sink risk on WhatsApp Web content script.
Evidence
- free_webmail_developer store Developer email dennerverli@gmail.com is free webmail; no verified publisher badge.
- brand_impersonation store brand_mention.is_impersonation=true; WhatsApp mentioned, developer domain is gmail.com, not Meta.
- privacy_policy_inadequate api Policy fetched but scope_extension=false, data_collection=false, third_party_silence=true; no extension-specific disclosure.
- dom_xss_sink crx dom_sink_innerhtml_userctrl in assets/content.js; no CSP to mitigate.
- no_csp manifest content_security_policy is null; csp_present=false on MV3 extension with DOM sink.
- reactjs_external_host crx js_external_hosts includes reactjs.org; external JS reference beyond dev-controlled domain.
- tiny_install_base store Only 12 installs; limited blast radius but also no community scrutiny.
- no_bad_hosts_or_cves api bad_host_hits=[], cve_findings_raw=[], monetization_hits=[], affiliate_hits=[] — no threat intel hits.
Permissions Breakdown
- storage low Stores local extension data; minimal risk.
- alarms low Schedules background tasks; no data access.
- identity low OAuth token access; scopes not declared, moderate risk in context.
- *://web.whatsapp.com/* medium Scoped host access to WhatsApp Web; matches stated CRM function.
- https://apimagisatende.magisia.com.br/* low Dev-controlled API endpoint; narrow scope.
Pillar Scores
Permissions1.60
Reputation7.00
Network0.00
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 04:47
Listing SHA
684f57f8f1df…
Force block
— not fired
Score recovered
no
Elapsed
—