Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

WA Self Sender & Easy Sender - Personalized WhatsApp Messages & Group Tools

khfmfdepnleebhonomgihppncahojfig
Risk Score
6.77
Risk Level: High
Recommendation: 🚫 BLOCK
Category Productivity
Installs 10,000
Rating 4.8
Last updated 2026-06-15
Manifest version MV3
CSP present ❌ no
Developer shuttershanti708@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE (CVE-2021-23358) in bundled underscore@1.8.3 enables arbitrary code execution; no CSP amplifies risk.
  • Content script declared for <all_urls> — far exceeds stated WhatsApp-only purpose; scope mismatch +1.0.
  • Privacy policy is Google's generic account policy (scope_extension=false, admits data collection + 3rd-party sharing) — +10.0 privacy pillar.
  • Brand impersonation of WhatsApp by unverified free-webmail developer (shuttershanti708@gmail.com) with no developer name.
  • Uninstall URL hijack confirmed; 12 external JS hosts including cdn2.waplus.io and third-party domains beyond dev control.

Evidence

  • critical_cve_underscore crx underscore@1.8.3 has CVE-2021-23358 (critical, arbitrary code execution); fixed in 1.12.1. No CSP present.
  • content_scripts_all_urls manifest content_scripts_matches includes <all_urls> — extension injects into every site despite WhatsApp-only stated purpose.
  • brand_impersonation_whatsapp store brand_mention.is_impersonation=true for WhatsApp; developer is unverified free-webmail gmail account, no developer name.
  • generic_google_privacy_policy store Privacy policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • uninstall_url_hijack crx uninstall_url_hijack=true — extension overrides uninstall redirect to third-party URL.
  • function_constructor_new_Function crx new Function() constructor found in js/background.js and pay/js/element-ui_2.15.14.js — dynamic code execution risk.
  • 12_external_js_hosts crx 12 distinct external hosts including cdn2.waplus.io, waselfsender.com, wawebsender.com, sheetjs.com beyond dev-owned domains.
  • no_csp_mv3 manifest content_security_policy is null; MV3 default applies but no explicit CSP hardening for CVE-bearing DOM-manipulation libs.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • activeTab low Access to current tab on user action only; limited scope.
  • storage low Local data persistence; low standalone risk.
  • unlimitedStorage low Removes storage quota; could store large harvested data sets.
  • scripting medium Programmatic script injection; high-impact when paired with broad host access.
  • *://*.whatsapp.com/* (host) high Full access to WhatsApp Web: can read/send messages, harvest contacts.
  • <all_urls> (content_scripts) high Content script declared for ALL URLs — far broader than stated WhatsApp purpose.

Pillar Scores

Permissions6.50
Reputation8.50
Network5.50
Webstore8.50
Maintenance0.00
Privacy10.00
Code Quality6.50
CVE Exposure7.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:49
Listing SHA 9a8d4ab1e8fb…
Force block — not fired
Score recovered no
Elapsed 35.7s