Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

DragonChat - Potencia tu WhatsApp

ieinlppbiopehpocmjjkkemalajklfel
Risk Score
3.36
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Productivity
Installs 683
Rating 5.0
Last updated 2026-08-18
Manifest version MV3
CSP present ✅ yes
Developer soporte@dragonchat.io
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but scope_extension=false and data_collection=false — no meaningful disclosure for this extension.
  • WhatsApp brand impersonation flagged; developer is not confirmed owner of WhatsApp brand.
  • Two innerHTML DOM-XSS sinks in content scripts running on WhatsApp Web; could process untrusted message content.
  • install_url_hijack: onInstall opens dragonchat.io/extension/changelog — low severity but non-standard.
  • api.ipify.org contact reveals user IP to third-party service; not disclosed in privacy policy.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true for 'whatsapp'; confirmed_owner=false; verified_publisher=true so +1.0 not +2.0.
  • privacy_policy_inadequate api scope_extension=false, data_collection=false, third_party_silence=true → pillar scored at 10.0 per v3 FIX A + +1.0 silence.
  • dom_xss_sinks crx 2x dom_sink_innerhtml_userctrl in dc-filters.js and dc-bulk-send.js; csp_present=true so base +0.5 each = +1.0 total.
  • install_url_hijack manifest onInstalled opens https://dragonchat.io/extension/changelog?v= — redirects to dev domain, low risk.
  • api_ipify_org crx Extension contacts api.ipify.org (IP geolocation third-party); not mentioned in privacy policy.
  • no_developer_name store developer_name is empty string; +1.0 reputation penalty applied.
  • verified_publisher store verified_publisher=true; -3.0 reputation discount applied (floored at 2.0 per hard floor).
  • host_geo_diversity api country_count=2 (CA, US); below threshold of 4, no geo-diversity penalty.

Permissions Breakdown

  • activeTab low Grants access only to the currently active tab on user action; limited scope.
  • storage low Local extension storage; no cross-origin risk.
  • https://web.whatsapp.com/* medium Content-script access to WhatsApp Web; can read messages and DOM.
  • https://*.dragonchat.io/* low Scoped to developer's own domain; expected for SaaS backend communication.

Pillar Scores

Permissions1.50
Reputation4.50
Network1.50
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 04:45
Listing SHA fba788bc10cb…
Force block — not fired
Score recovered no
Elapsed