Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

IMPAR CRM

jdihogecojffhidcdpcnpgbbegaeofnj
Risk Score
3.59
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Productivity
Installs 7
Rating 5.0
Last updated 2026-05-15 (4 months ago)
Manifest version MV3
CSP present ❌ no
Developer wl.exten.02@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Free-webmail Gmail developer with no verified identity injects JS into WhatsApp Web.
  • Brand impersonation: uses 'WhatsApp' branding without being Meta/affiliated.
  • install_url_hijack opens web.whatsapp.com on install — minor but indicative behavior.
  • No CSP on MV3 extension with innerHTML DOM-XSS sink in vendor bundle.
  • Privacy policy domain (opt-api.com) differs from developer identity; third-party sharing admitted.

Evidence

  • free_webmail_developer store Developer email wl.exten.02@gmail.com — free webmail, numbered alias, no verified business.
  • brand_impersonation store brand_mention.is_impersonation=true for 'whatsapp'; developer is not Meta/verified owner.
  • install_url_hijack crx install_url_hijack=true; opens https://web.whatsapp.com on install.
  • dom_xss_sink crx dom_sink_innerhtml_userctrl in vendor.BaH-a-x7.js; no CSP present to mitigate.
  • privacy_policy_third_party api Privacy policy admits data collection and third-party sharing; hosted on opt-api.com.
  • content_script_whatsapp manifest Content script on https://web.whatsapp.com/* can read/manipulate all WhatsApp Web content.
  • js_external_hosts crx External JS hosts: hc-stt.hiperchat.com.br, reactjs.org, web.whatsapp.com.
  • low_installs store Only 7 installs; unvetted by user community.

Permissions Breakdown

  • unlimitedStorage low Allows storing large data locally; limited external risk.
  • storage low Standard local key-value storage; low risk.
  • tabs medium Can read tab URLs and titles; moderate privacy exposure.
  • alarms low Scheduling only; no data access.
  • content_scripts: https://web.whatsapp.com/* medium Injects JS into WhatsApp Web; can read/write page content including messages.

Pillar Scores

Permissions2.30
Reputation7.50
Network2.00
Webstore5.00
Maintenance1.50
Privacy0.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 16:08
Listing SHA 8902e33a94be…
Force block — not fired
Score recovered no
Elapsed