Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

InfinyZap

ioimkgpmigbhaddpgmbjjddoaagialah
Risk Score
4.52
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 8
Rating 5.0
Last updated 2026-08-25
Manifest version MV3
CSP present ❌ no
Developer Infinyzap@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's own policy — not scoped to this extension; admits data collection and third-party sharing.
  • Cookie access on WhatsApp Web enables exfiltration of active session tokens.
  • No CSP declared (MV3 default only); innerHTML sinks in 3 JS files create DOM-XSS exposure.
  • new Function() constructor in app.js enables dynamic code execution.
  • Free-webmail dev (gmail), no developer name, 8 installs but holds high-tier permissions — tail attack surface.

Evidence

  • privacy_policy_generic store Policy URL is Google's account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 D).
  • cookies_on_whatsapp manifest cookies permission + host_permission https://web.whatsapp.com/* — can read WhatsApp session cookies.
  • function_constructor crx new Function() in app.js — dynamic code execution risk (+2.5 code quality).
  • dom_sink_innerHTML_no_csp crx innerHTML sinks in 3 files with csp_present=false → +2.0 each (FIX B), capped.
  • free_webmail_no_devname store Developer email is gmail, developer_name empty → reputation floor 7.5.
  • small_install_high_perm api 8 installs but has_high_tier_permission=true, small_install_high_perm=true → +1.5 webstore.
  • js_external_hosts crx External JS hosts: notiflix.github.io, reactjs.org — loaded from content scripts context.
  • no_csp_mv3 manifest csp_present=false on MV3; no explicit CSP amplifies innerHTML/Function risks.

Permissions Breakdown

  • storage low Standard local data storage, low risk.
  • unlimitedStorage low Extends storage quota, minimal risk.
  • tabs medium Can read tab URLs and metadata.
  • cookies high Access to cookies on permitted hosts including WhatsApp session cookies.
  • notifications low Can show desktop notifications.
  • declarativeNetRequest medium Can block/redirect network requests per static rules.
  • https://web.whatsapp.com/* high Full access to WhatsApp Web — can read/modify messages and sessions.
  • https://app.coderlicences.com/* medium Contacts unknown third-party license server; data flow opaque.

Pillar Scores

Permissions6.50
Reputation7.50
Network4.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 04:49
Listing SHA 787aeb70d1bf…
Force block — not fired
Score recovered no
Elapsed