B2Cor CRM e Funil de Vendas - agencialink.com
jpifkbikhaakajfklldhhhfpakaflndi
Risk Score
3.41
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and third-party sharing (Privacy pillar: 10.0).
- No developer name listed; reduces accountability for a WhatsApp-integrated CRM tool.
- Install URL hijack redirects to https://web.whatsapp.com/ on install — minor but adds Webstore risk.
- Content script on WhatsApp Web can read chat content; combined with outbound calls to crm-b2cor.agencialink.com.br this is a data-exfil surface.
- stackoverflow.com in js_external_hosts is unexplained and unusual for a CRM extension.
Evidence
- privacy_policy_generic store Policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 Privacy per v3.5 rule D.
- install_url_hijack manifest install_url_hijack=true targeting https://web.whatsapp.com/ — triggers +2.0 Webstore.
- no_developer_name store developer_name is empty; +1.0 Reputation penalty applied.
- content_script_whatsapp manifest Content script scoped to https://web.whatsapp.com/* — reads chat DOM; outbound to crm-b2cor.agencialink.com.br creates exfil surface.
- stackoverflow_external_host crx stackoverflow.com listed in js_external_hosts — no obvious reason for a CRM tool to contact it.
- no_csp manifest csp_present=false on MV3; MV3 has strict defaults so no Network penalty, but raises code-quality awareness.
- no_cve_findings crx cve_findings_raw is empty; CVE pillar = 0.0.
- no_obfuscation_no_code_findings crx obfuscation_score=0.0, code_findings_raw empty; code quality pillar = 0.0.
Permissions Breakdown
- activeTab low Grants access only to the currently active tab on user interaction; minimal standing access.
- content_scripts: https://web.whatsapp.com/* medium Injects JS into WhatsApp Web; can read conversation data on that origin.
Pillar Scores
Permissions0.30
Reputation6.00
Network0.00
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 04:55
Listing SHA
c662c812f6c4…
Force block
— not fired
Score recovered
no
Elapsed
—