Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Privacy Extension for WhatsApp web

jpmdniboiipfcjdibpahdbibookdhmji
Risk Score
3.22
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category PrivacyTool
Installs 20,000
Rating 4.7
Last updated 2026-06-03
Manifest version MV3
CSP present ❌ no
Developer rahul.1990tech@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: extension names WhatsApp but confirmed_owner==false and dev uses free Gmail account.
  • identity.email permission is unnecessary for a privacy/hide-status tool — collects Google account email.
  • Privacy policy URL is the Chrome Web Store listing page itself, not a real policy; scope_extension=true but third_party_sharing=true with no retention disclosure.
  • install_url_hijack to premiumsender.com on install — monetization/tracking site linked at install time.
  • No CSP declared (MV3 mitigates somewhat) and external JS hosts include premiumsender.com.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true for 'whatsapp'; developer is gmail user, not Meta/WhatsApp Inc.
  • install_url_hijack manifest onInstalled opens https://premiumsender.com/privacy-extension-for-whatsapp-web/ — 3rd-party monetization domain.
  • identity_email_permission manifest identity + identity.email declared; no stated need for Google account email in a WhatsApp privacy tool.
  • privacy_policy_inadequate store Policy URL resolves to own CWS listing (510KB store page). third_party_sharing=true, retention=false.
  • free_webmail_developer store Developer email rahul.1990tech@gmail.com — numbered-alias Gmail, no verified business domain.
  • external_js_hosts crx js_external_hosts includes premiumsender.com and react.dev; premiumsender.com is install-hijack target.
  • verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; discounts reputation but capped due to brand impersonation.
  • no_csp manifest content_security_policy=null; MV3 enforces strict default but no explicit CSP tightening declared.

Permissions Breakdown

  • tabs medium Can read tab URLs and metadata; moderate risk scoped to WhatsApp use.
  • storage low Local data persistence only; no cross-site exfil concern.
  • identity medium OAuth token access; combined with identity.email raises account-linkage risk.
  • identity.email medium Reads user's Google account email; unnecessary for a WhatsApp privacy tool.
  • https://web.whatsapp.com/* medium Host permission limited to WhatsApp web only; scoped but sensitive messaging context.

Pillar Scores

Permissions3.30
Reputation6.50
Network2.00
Webstore5.50
Maintenance0.00
Privacy2.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-15 14:22
Listing SHA c58e84c7347e…
Force block — not fired
Score recovered no
Elapsed 23.2s