Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Botzaper Premium

klhdlmakggjklhafembcfpopdoideecl
Risk Score
4.52
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 3
Rating
Last updated 2025-09-29 (12 months ago)
Manifest version MV3
CSP present ❌ no
Developer startupagencia.adm@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's own policy — not scoped to this extension, admits data collection and 3rd-party sharing.
  • WhatsApp impersonation brand mention by unverified gmail developer; content scripts can exfiltrate messages.
  • Install URL hijack on onInstalled opens 3rd-party URL, a monetization/tracking pattern.
  • Audio transcription endpoint (audio-transcriber.wascript.com.br) may receive sensitive voice data from WhatsApp.
  • No CSP with function_constructor usage across 896 JS files; dynamic code execution risk.

Evidence

  • privacy_policy_google_generic store Policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true — worst-case generic policy.
  • brand_impersonation store brand_mention.is_impersonation=true for WhatsApp; developer is unverified gmail user, not Meta.
  • install_url_hijack manifest install_url_hijack=true; onInstalled opens 3rd-party URL — common monetization/tracking shell pattern.
  • function_constructor_no_csp crx 3 instances of new Function() constructor across JS bundle; csp_present=false amplifies dynamic code execution risk.
  • whatsapp_host_permission manifest Full scripting access to web.whatsapp.com; combined with audio/message API endpoints, broad message data exposure.
  • geo_diversity crx JS hosts span 4 countries (BR, CA, LT, US); LT presence is unusual for a BR WhatsApp productivity tool.
  • gmail_dev_no_business store Developer email startupagencia.adm@gmail.com is free-webmail; no verified publisher; developer_domain_info=null.
  • external_backend_lotsofwms_in manifest host_permission includes backend.lotsofwms.in — third-party .in domain unrelated to developer identity.

Permissions Breakdown

  • unlimitedStorage low Allows large local data storage; low direct harm alone.
  • storage low Standard local key-value store; low risk.
  • alarms low Scheduling only; low risk.
  • tabs medium Can read tab URLs and metadata across all open tabs.
  • scripting medium Can inject scripts into matching pages (WhatsApp); significant capability.
  • https://web.whatsapp.com/* high Full DOM/script access to WhatsApp Web; can read messages and contacts.
  • https://backend.lotsofwms.in/* medium External backend in .in TLD; unclear ownership, potential data exfil target.
  • https://backend-utils.wascript.com.br/* medium Developer-controlled backend; data routing unknown.
  • https://audio-transcriber.wascript.com.br/* medium Audio data may be sent to this endpoint; sensitive content risk.
  • https://api-whatsapp.wascript.com.br/* medium WhatsApp-specific API endpoint; message data could be forwarded.
  • https://multi-atendimento.wascript.com.br/* medium Multi-attendance backend; conversation data exposure risk.
  • https://botzaper.digital/* medium Primary product domain; data aggregation point.

Pillar Scores

Permissions4.30
Reputation7.50
Network4.50
Webstore5.50
Maintenance3.50
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 16:55
Listing SHA 3358f618493e…
Force block — not fired
Score recovered no
Elapsed