Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

WhatsApp™ Number Generator & Checker - ExtBoost

ipbgdicbhbblkaabpgkhkhebjjfdcbah
Risk Score
4.90
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category Other
Installs 102
Rating 5.0
Last updated 2026-08-26 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer exportmyinfohq@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • WhatsApp brand impersonation by unverified free-webmail developer (exportmyinfohq@gmail.com) with no developer name.
  • Content script on <all_urls> + https://*.whatsapp.com/* exposes all browsing and WhatsApp session/messages.
  • identity + identity.email permissions allow silent Google account email harvest.
  • Privacy policy admits third-party data sharing without scoping to this extension; no retention period disclosed.
  • Small-install (102) high-permission anomaly signals possible targeted or experimental exfil tool.

Evidence

  • brand_impersonation store Title uses WhatsApp™ trademark; developer domain is gmail.com, confirmed_owner=false, is_impersonation=true.
  • free_webmail_no_dev_name store developer_email=exportmyinfohq@gmail.com, developer_name empty; no verified business identity.
  • broad_host_access manifest host_permissions=[https://*/*] + content_scripts on <all_urls> grants universal page access.
  • whatsapp_content_script manifest Dedicated content script on https://*.whatsapp.com/* can read messages, contacts, session tokens.
  • identity_email_permission manifest identity + identity.email can silently retrieve signed-in Google account email via OAuth.
  • dom_xss_sinks crx 3 innerHTML-from-variable sinks found; no CSP present (csp_present=false), elevating XSS risk.
  • privacy_policy_third_party_sharing api Policy fetched: scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
  • small_install_high_perm_anomaly store 102 installs with HIGH-tier permissions; install_perm_anomaly.small_install_high_perm=true.

Permissions Breakdown

  • storage low Local state persistence; low standalone risk.
  • identity medium Can obtain OAuth tokens; risk amplified by gmail-only dev identity.
  • identity.email medium Reads signed-in Google account email; PII exfil surface.
  • https://*/* high Broad host access across all HTTPS sites; HIGH tier.
  • <all_urls> (content_script) high Content script injected on all URLs, reads/modifies any page DOM.
  • https://*.whatsapp.com/* (content_script) high Direct access to WhatsApp session data, messages, contacts.

Pillar Scores

Permissions6.50
Reputation7.50
Network2.00
Webstore7.00
Maintenance0.00
Privacy2.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 16:13
Listing SHA 2b5d5e799ec7…
Force block — not fired
Score recovered no
Elapsed