Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

PharmaZap

jbjpfhemoolhegecihahbkfhaohohacd
Risk Score
6.54
Risk Level: High
Recommendation: 🚫 BLOCK
Category Productivity
Installs 49
Rating 5.0
Last updated 2026-07-31 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer christian.pharmapro@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • cookies permission + WhatsApp host access enables WhatsApp session cookie theft/exfil.
  • Privacy policy is Google's own policy — not scoped to this extension; admits data collection + 3rd-party sharing.
  • Free Gmail dev email, no dev name, no verified publisher — low accountability.
  • function_constructor + multiple innerHTML DOM-XSS sinks with no CSP elevate code-execution risk.
  • Low install count (49) with high-tier permissions is a tail-attack-surface anomaly.

Evidence

  • cookies+WhatsApp host manifest cookies permission paired with https://web.whatsapp.com/* enables full session cookie access to WhatsApp Web.
  • generic privacy policy store Privacy URL is Google's own policy (myaccount.google.com); scope_extension=false, data_collection=true, third_party_sharing=true.
  • free webmail dev, no name store Developer email christian.pharmapro@gmail.com; developer_name empty; no verified publisher badge.
  • function_constructor in app.js crx new Function() call detected in app.js — dynamic code execution risk.
  • 3x innerHTML DOM-XSS sinks crx innerHTML assigned from variables in app.js, background.js, contentScript.js with no CSP present.
  • no CSP manifest content_security_policy is null/absent; amplifies all code-quality findings.
  • unknown licensing endpoint manifest https://app.coderlicences.com/* in host_permissions — unverified third-party domain.
  • install_perm_anomaly api 49 installs with high-tier permissions (cookies, tabs); small_install_high_perm=true.

Permissions Breakdown

  • storage low Persists local extension data; low risk.
  • unlimitedStorage low Removes storage quota; low standalone risk.
  • tabs medium Can read tab URLs and metadata across browser.
  • cookies high Can read/write cookies; combined with host perms on WhatsApp is session-theft risk.
  • notifications low Can push desktop notifications; low risk.
  • declarativeNetRequest medium Can modify/block network requests declaratively.
  • https://web.whatsapp.com/* high Full script+cookie access to WhatsApp Web; session exfil risk.
  • https://app.coderlicences.com/* medium Unknown third-party licensing endpoint; data flows outside WhatsApp scope.

Pillar Scores

Permissions6.50
Reputation8.00
Network5.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 11:16
Listing SHA 9112bf25e91f…
Force block — not fired
Score recovered no
Elapsed