Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

EaseZap

jlplnjdjnhkdigmpooonjmjppdkahljh
Risk Score
3.71
Risk Level: Low
Recommendation: 🚫 BLOCK
Category Productivity
Installs 22
Rating 5.0
Last updated 2026-08-26
Manifest version MV3
CSP present ❌ no
Developer contato@extensao.store
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall AND install URL hijack: extension intercepts browser lifecycle events to redirect users to third-party URLs.
  • Privacy policy is Google's own policy (generic, unscoped) — admits data collection and third-party sharing with no extension-specific scope.
  • WhatsApp brand impersonation: developer domain (extensao.store) is not affiliated with Meta/WhatsApp.
  • 10 external JS hosts under wascript.com.br / watools.com.br contacted at runtime — large unverified backend surface.
  • new Function() constructor in content script running on WhatsApp Web enables dynamic code execution against chat data.

Evidence

  • install/uninstall URL hijack crx uninstall_url_hijack=true, install_url_hijack=true with target https://web.whatsapp.com — lifecycle events abused.
  • generic Google privacy policy store Policy URL is myaccount.google.com/privacypolicy — not scoped to EaseZap; data_collection+third_party_sharing=true.
  • WhatsApp brand impersonation store brand_mention.is_impersonation=true; dev domain extensao.store not affiliated with Meta.
  • 10 external JS hosts crx Contacts api-whatsapp.wascript.com.br, app.wascript.com.br, backend-plugin.wascript.com.br + 7 more at runtime.
  • function_constructor in content script crx new Function() found in content script on WhatsApp Web — allows dynamic code execution against chat session.
  • innerHTML DOM-XSS sink crx Unguarded innerHTML assignment in content script without CSP; DOM-XSS risk in WhatsApp context.
  • no CSP + MV3 manifest csp_present=false; MV3 has strict default but no explicit CSP declared alongside 334 JS files.
  • very low install count store Only 22 installs; unverified publisher, no ratings count — minimal community validation.

Permissions Breakdown

  • unlimitedStorage low Allows unbounded local storage; low direct harm but enables large local data accumulation.
  • storage low Standard key-value storage; low risk in isolation.
  • alarms low Scheduled tasks only; low risk.
  • tabs medium Can read tab URLs and titles; medium risk when combined with WhatsApp host access.
  • https://web.whatsapp.com/* medium Scoped host access to WhatsApp Web; can read/modify all WhatsApp chat content.

Pillar Scores

Permissions2.30
Reputation7.00
Network4.00
Webstore8.00
Maintenance0.00
Privacy10.00
Code Quality4.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 04:31
Listing SHA f14d4ea3fc95…
Force block — not fired
Score recovered no
Elapsed