HUMANERGY CRM
icchpmlociodmljbjhlojgfamhccbbcd
Risk Score
4.08
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic policy — not scoped to this extension; admits data collection and third-party sharing.
- Content script injected into WhatsApp Web can read conversation content and DOM; developer uses free webmail with no verified identity.
- Free-webmail developer (gmail) with only 12 installs and no business domain verified; throwaway-account risk.
- 11 external JS hosts contacted including cdn.jsdelivr.net, crm.humanergy-tools.com, and multiple tracking/logistics sites beyond WhatsApp scope.
- new Function() constructor found in bundled JS; dynamic code execution risk even without obfuscation.
Evidence
- privacy_policy_generic store Policy URL is Google's own privacy page; scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 Privacy (v3.5 rule D).
- free_webmail_developer store Developer email bmasconsultingmx@gmail.com; no verified publisher badge; no business domain; reputation start 5+1.5=6.5.
- content_script_whatsapp manifest Content script on https://web.whatsapp.com/* allows reading all WhatsApp Web DOM including messages.
- external_hosts_broad crx 12 distinct external JS hosts: cdn.jsdelivr.net, crm.humanergy-tools.com, t.17track.net, www.muambator.com.br, etc. >3 domains.
- function_constructor crx new Function() constructor found in JS bundle — dynamic code execution vector.
- no_csp manifest csp_present=false on MV3 extension; MV3 has strict default CSP so no extra penalty applied, but no custom CSP declared.
- maintenance_6_12mo store months_since_update=8; falls in 6-12 month band (+3.5).
- no_cve_findings crx cve_findings_raw is empty; jquery 3.7.1 and react 17.0.2/16.13.1 bundled but no CVEs reported.
Permissions Breakdown
- unlimitedStorage low Allows storing large amounts of local data; low risk alone.
- storage low Standard local storage access, no cross-origin exposure.
- alarms low Scheduling API; minimal risk on its own.
- tabs medium Can read tab URLs and titles; moderate info-disclosure risk.
- content_scripts: https://web.whatsapp.com/* medium Injects JS into WhatsApp Web; can read messages and DOM content on that domain.
Pillar Scores
Permissions1.90
Reputation6.50
Network3.50
Webstore2.00
Maintenance3.50
Privacy10.00
Code Quality2.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 11:42
Listing SHA
9180ce6112fe…
Force block
— not fired
Score recovered
no
Elapsed
—