Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

SevenSales

gmidblfofjdiajmlnfiagijikmojkhia
Risk Score
5.38
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 66
Rating 5.0
Last updated 2026-08-26
Manifest version MV3
CSP present ❌ no
Developer contato@extensao.store
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy points to Google's own policy — not scoped to this extension; admits data collection & third-party sharing.
  • Uninstall AND install URL hijack flagged; install redirects to web.whatsapp.com suggesting tracking.
  • Brand impersonation: extension uses 'WhatsApp' and 'Google' brands without being a confirmed owner.
  • 10 distinct external wascript.com.br / watools.com.br API hosts contacted from a 66-install WhatsApp extension.
  • new Function() constructor found in content script running inside WhatsApp Web session — arbitrary code exec risk.

Evidence

  • privacy_policy_generic_google store Privacy URL is Google's own policy (scope_extension=false, data_collection=true, third_party_sharing=true) — D clause applies: +10.0.
  • uninstall_url_hijack + install_url_hijack crx Both onInstalled and uninstall URL hijacks flagged; install_url_target=https://web.whatsapp.com.
  • brand_impersonation store brand_mention.is_impersonation=true for WhatsApp and Google; developer is not confirmed owner.
  • js_external_hosts crx 10 distinct wascript.com.br/watools.com.br subdomains contacted; >3 distinct registrable domains.
  • function_constructor crx new Function() in content script scoped to WhatsApp Web — dynamic code execution risk.
  • dom_sink_innerhtml_userctrl crx innerHTML from variable with no CSP present — DOM-XSS sink elevated to +2.0 (csp_present==false).
  • no_csp manifest content_security_policy is null (MV3 but csp_present=false); no inline-script protection.
  • low_installs_high_external_surface store Only 66 installs but 334 JS files and 10 external API domains — disproportionate backend footprint.

Permissions Breakdown

  • unlimitedStorage low Allows unrestricted local storage; low direct harm but can cache large data.
  • storage low Standard local key-value storage; minimal risk.
  • alarms low Scheduled tasks; low risk, used for CRM reminders.
  • tabs medium Can read tab URLs and titles; moderate surveillance surface.
  • https://web.whatsapp.com/* medium Host permission scoped to WhatsApp Web; allows content injection into messaging session.

Pillar Scores

Permissions2.30
Reputation7.00
Network3.50
Webstore8.00
Maintenance0.00
Privacy10.00
Code Quality4.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 10:40
Listing SHA 0ad127f082b2…
Force block — not fired
Score recovered no
Elapsed