Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

HUMANERGY CRM

icchpmlociodmljbjhlojgfamhccbbcd
Risk Score
4.08
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 12
Rating 5.0
Last updated 2025-12-17 (8 months ago)
Manifest version MV3
CSP present ❌ no
Developer bmasconsultingmx@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy — not scoped to this extension; admits data collection and third-party sharing.
  • Content script injected into WhatsApp Web can read conversation content and DOM; developer uses free webmail with no verified identity.
  • Free-webmail developer (gmail) with only 12 installs and no business domain verified; throwaway-account risk.
  • 11 external JS hosts contacted including cdn.jsdelivr.net, crm.humanergy-tools.com, and multiple tracking/logistics sites beyond WhatsApp scope.
  • new Function() constructor found in bundled JS; dynamic code execution risk even without obfuscation.

Evidence

  • privacy_policy_generic store Policy URL is Google's own privacy page; scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 Privacy (v3.5 rule D).
  • free_webmail_developer store Developer email bmasconsultingmx@gmail.com; no verified publisher badge; no business domain; reputation start 5+1.5=6.5.
  • content_script_whatsapp manifest Content script on https://web.whatsapp.com/* allows reading all WhatsApp Web DOM including messages.
  • external_hosts_broad crx 12 distinct external JS hosts: cdn.jsdelivr.net, crm.humanergy-tools.com, t.17track.net, www.muambator.com.br, etc. >3 domains.
  • function_constructor crx new Function() constructor found in JS bundle — dynamic code execution vector.
  • no_csp manifest csp_present=false on MV3 extension; MV3 has strict default CSP so no extra penalty applied, but no custom CSP declared.
  • maintenance_6_12mo store months_since_update=8; falls in 6-12 month band (+3.5).
  • no_cve_findings crx cve_findings_raw is empty; jquery 3.7.1 and react 17.0.2/16.13.1 bundled but no CVEs reported.

Permissions Breakdown

  • unlimitedStorage low Allows storing large amounts of local data; low risk alone.
  • storage low Standard local storage access, no cross-origin exposure.
  • alarms low Scheduling API; minimal risk on its own.
  • tabs medium Can read tab URLs and titles; moderate info-disclosure risk.
  • content_scripts: https://web.whatsapp.com/* medium Injects JS into WhatsApp Web; can read messages and DOM content on that domain.

Pillar Scores

Permissions1.90
Reputation6.50
Network3.50
Webstore2.00
Maintenance3.50
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 11:42
Listing SHA 9180ce6112fe…
Force block — not fired
Score recovered no
Elapsed