Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Privacy Extension For WhatsApp Web

jbojhlhhggfmmkpefknmbdhlaghehini
Risk Score
3.45
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category PrivacyTool
Installs 1,000,000
Rating 2.7
Last updated 2026-08-03 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer aryo.muzakki@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: extension uses 'WhatsApp' brand name and is not owned/verified by Meta.
  • Privacy policy URL points to Chrome Web Store listing page, not a real policy; third_party_sharing admitted without scope.
  • Rating of 2.7 across a large install base (1M) suggests quality or trust concerns from real users.
  • No developer name listed in store; identity accountability is weak.
  • Stale: 15 months since last update on an extension with 1M installs and no CSP raises option-value risk.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true for 'whatsapp'; confirmed_owner=false; developer is lukaslen.com, not Meta.
  • privacy_policy_url_invalid store Privacy policy URL is the extension's own CWS listing page, not a standalone policy document.
  • privacy_third_party_sharing api privacy_policy_classification: scope_extension=true, data_collection=false, third_party_sharing=true, retention=false.
  • low_rating store Rating 2.7 on 1M-install extension; no review red flags in structured scan but low score is notable.
  • no_developer_name store developer_name is empty string; only contact@lukaslen.com available for attribution.
  • stale_extension store months_since_update=15; in 6-12 month band for maintenance scoring.
  • no_csp manifest content_security_policy=null; MV3 has strict default so no extra Network penalty, but dom-sink risk unmitigated.
  • verified_publisher store verified_publisher=true; applies reputation discount but impersonation overrides full benefit per v3.2 rule (9).

Permissions Breakdown

  • storage low Stores extension preferences locally; minimal risk.
  • host_permission: https://web.whatsapp.com/* medium Scoped to WhatsApp Web only; matches stated function as a WhatsApp privacy tool.
  • content_scripts: https://web.whatsapp.com/* medium Injects scripts into WhatsApp Web; consistent with stated purpose but grants DOM access.

Pillar Scores

Permissions1.30
Reputation5.50
Network0.00
Webstore3.50
Maintenance6.00
Privacy2.00
Code Quality0.00
CVE Exposure0.00

Scoring History

sssiednd56c5bc5dp727562726963xsx 2.79 Low review 2026-09-07
%F6"onmouseover=dMam(96645)// 2.83 Low review 2026-08-05
dfb{{98991*97996}}xca 1.96 Low review 2026-08-05
bfg8966<s1﹥s2ʺs3ʹhjl8966 2.83 Low review 2026-08-05
v3.6&n930880=v937066 2.88 Low review 2026-08-05
v3.6"><script>nTUJ(9319)</script> 2.76 Low review 2026-08-04
v3.6"onmouseover=nTUJ(90812)" 2.16 Low review 2026-08-04
bfg10289<s1﹥s2ʺs3ʹhjl10289 2.65 Low review 2026-08-04
v3.6&n950672=v953334 2.70 Low review 2026-08-04
v3.6"sTYLe='zzz:Expre/**/SSion(NdJi(9059))'bad=" 3.05 Low review 2026-07-29
v3.6"onmouseover=NdJi(96282)" 2.81 Low review 2026-07-29
1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%> 3.06 Low review 2026-07-29
"dfbzzzzzzzzbbbccccdddeeexca".replace("z","o") 3.00 Low review 2026-07-29
<th:t="${dfb}#foreach 2.50 Low review 2026-07-29
v3.69406329< 3.34 Low review 2026-07-29
v3.6'"()&%<zzz><ScRiPt >NdJi(9467)</ScRiPt> 2.72 Low review 2026-07-29
v3.6&n913574=v945062 2.67 Low review 2026-07-29
v3.6 3.45 Low review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:44
Listing SHA 7413ad753287…
Force block — not fired
Score recovered no
Elapsed 20.2s