Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

WhatsBlast — WhatsApp Bulk Sender + CRM | Leadgrabr

jnghfafinjlkhgfbphnldgchmbahkjma
Risk Score
4.06
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 7
Rating 5.0
Last updated 2026-05-16 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer Akshay.kini@leadgrabr.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • WhatsApp brand impersonation: dev domain is leadgrabr.com, not Meta/WhatsApp — unverified third party.
  • Privacy policy is 58 chars, not extension-scoped, and admits no data collection — likely placeholder.
  • Content script on web.whatsapp.com reads live chat DOM; bulk-sender function has high message-abuse potential.
  • External JS host cool-cake-8a5d.akshay-kini.workers.dev (Cloudflare Worker) creates supply-chain risk.
  • Two DOM-XSS innerHTML sinks in CRM and popup code with no CSP to mitigate.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true for WhatsApp; dev domain leadgrabr.com not confirmed owner.
  • privacy_policy_stub api Policy fetched but only 58 chars; scope_extension=false, data_collection=false — likely placeholder.
  • external_worker_host crx js_external_hosts includes cool-cake-8a5d.akshay-kini.workers.dev — personal Cloudflare Worker.
  • dom_xss_sink crx Two innerHTML sinks in crm-panel.js and popup.js; no CSP present (MV3 default only).
  • no_developer_name store developer_name is empty string; only email Akshay.kini@leadgrabr.com available.
  • whatsapp_content_script manifest Content script runs on https://web.whatsapp.com/* — full chat DOM access including messages and contacts.
  • no_verified_publisher store verified_publisher=false, is_featured_by_google=false; 7 installs only.
  • third_party_silence api privacy_policy_classification.third_party_silence=true; policy does not mention third-party sharing.

Permissions Breakdown

  • storage low Stores local CRM/contact data; scoped to extension.
  • tabs medium Can read tab URLs; needed to detect WhatsApp Web tab.
  • alarms low Schedules reminders; low abuse potential alone.
  • notifications low Sends desktop notifications; no data exfil risk.
  • host: https://web.whatsapp.com/* medium Content script on WhatsApp Web — can read chat DOM, contacts, messages.

Pillar Scores

Permissions2.30
Reputation7.00
Network2.50
Webstore3.50
Maintenance0.00
Privacy9.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 04:41
Listing SHA 17987fbc8df9…
Force block — not fired
Score recovered no
Elapsed