Cubo Conecta
imhedlpapnopjkbnhojdcknleolmjnbg
Risk Score
4.04
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic policy — not scoped to this extension, admits data collection and third-party sharing (Privacy +10.0).
- Brand impersonation: WhatsApp mentioned in description/content-scripts but developer is unverified as Meta (Reputation +2.0).
- Uninstall URL hijack flag set (uninstall_url_hijack=true) — redirects user on removal (Webstore +3.0).
- Content script on web.whatsapp.com can read/modify all WhatsApp Web content including messages and contact data.
- No content_security_policy (MV3 default applies but CSP absent increases risk surface for injected scripts).
Evidence
- uninstall_url_hijack manifest chrome.runtime.setUninstallURL() set to third-party target; triggers +3.0 Webstore penalty.
- brand_impersonation_whatsapp store brand_mention.is_impersonation=true for WhatsApp; developer not confirmed as Meta owner.
- generic_google_privacy_policy api Policy URL is myaccount.google.com/privacypolicy — fetched, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy (v3.5 D rule).
- content_script_whatsapp manifest Content script injected into web.whatsapp.com — can read messages, contacts, session tokens.
- no_cve_findings crx cve_findings_raw empty; vue 3.5.25 bundled — no known CVEs detected.
- obfuscation_clean crx obfuscation_score=0.0, code_findings_raw empty; code quality appears clean.
- developer_domain_resolves api cubocrm.com.br resolves, looks_throwaway=false; legitimate Brazilian CRM business signal.
- no_operator_siblings api operator_cluster.sibling_count=0; no cluster risk.
Permissions Breakdown
- storage low Local key-value storage only; no cross-site data exposure.
- host: https://next.cubosuite.com.br/* low Scoped to developer's own backend domain; consistent with CRM function.
- content_script: https://web.whatsapp.com/* medium Reads/modifies WhatsApp Web DOM; can intercept messages and contacts.
- content_script: https://www.google.com/maps/* low Scoped to Maps; limited data exposure risk.
- content_script: https://www.google.com/search* low Scoped to Google Search results; moderate data exposure.
- content_script: https://www.google.com/sorry/* low CAPTCHA page only; negligible risk.
Pillar Scores
Permissions2.00
Reputation6.50
Network1.50
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 04:49
Listing SHA
77d425881bcf…
Force block
— not fired
Score recovered
no
Elapsed
—