Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

B2Cor CRM e Funil de Vendas - agencialink.com

jpifkbikhaakajfklldhhhfpakaflndi
Risk Score
3.41
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Productivity
Installs 1,000
Rating 5.0
Last updated 2026-08-05
Manifest version MV3
CSP present ❌ no
Developer suporte@agencialink.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and third-party sharing (Privacy pillar: 10.0).
  • No developer name listed; reduces accountability for a WhatsApp-integrated CRM tool.
  • Install URL hijack redirects to https://web.whatsapp.com/ on install — minor but adds Webstore risk.
  • Content script on WhatsApp Web can read chat content; combined with outbound calls to crm-b2cor.agencialink.com.br this is a data-exfil surface.
  • stackoverflow.com in js_external_hosts is unexplained and unusual for a CRM extension.

Evidence

  • privacy_policy_generic store Policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 Privacy per v3.5 rule D.
  • install_url_hijack manifest install_url_hijack=true targeting https://web.whatsapp.com/ — triggers +2.0 Webstore.
  • no_developer_name store developer_name is empty; +1.0 Reputation penalty applied.
  • content_script_whatsapp manifest Content script scoped to https://web.whatsapp.com/* — reads chat DOM; outbound to crm-b2cor.agencialink.com.br creates exfil surface.
  • stackoverflow_external_host crx stackoverflow.com listed in js_external_hosts — no obvious reason for a CRM tool to contact it.
  • no_csp manifest csp_present=false on MV3; MV3 has strict defaults so no Network penalty, but raises code-quality awareness.
  • no_cve_findings crx cve_findings_raw is empty; CVE pillar = 0.0.
  • no_obfuscation_no_code_findings crx obfuscation_score=0.0, code_findings_raw empty; code quality pillar = 0.0.

Permissions Breakdown

  • activeTab low Grants access only to the currently active tab on user interaction; minimal standing access.
  • content_scripts: https://web.whatsapp.com/* medium Injects JS into WhatsApp Web; can read conversation data on that origin.

Pillar Scores

Permissions0.30
Reputation6.00
Network0.00
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 04:55
Listing SHA c662c812f6c4…
Force block — not fired
Score recovered no
Elapsed