Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Indutiva CRM

ldgfbmnjkfncahaljnceanjaabkbjnca
Risk Score
4.07
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs
Rating
Last updated
Manifest version MV3
CSP present ❌ no
Developer
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy — not scoped to this extension, admits data collection and 3rd-party sharing (Privacy pillar: 10).
  • WhatsApp brand mentioned; developer not confirmed owner — impersonation flag raised.
  • Content script on web.whatsapp.com can read WhatsApp Web DOM including chat content.
  • No developer identity, no install count, no rating — unverifiable provenance.
  • DOM-XSS sink (innerHTML) present with no CSP — risk of DOM injection if CRM API returns attacker-controlled content.

Evidence

  • privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • brand_impersonation crx brand_mention: whatsapp mentioned, confirmed_owner=false, is_impersonation=true.
  • whatsapp_content_script manifest Content script injected into https://web.whatsapp.com/* — reads chat UI and DOM.
  • dom_xss_sink crx innerHTML assignment in LoginForm-DbDpxlKu.js; no CSP present (MV3 default strict, but csp_present=false).
  • no_developer_identity store developer_name, developer_email, install count, rating all missing — unverifiable.
  • external_host_reactjs_org crx js_external_hosts includes reactjs.org — likely redirect/banner URL, not code load.
  • no_bad_hosts api threat_intel.bad_host_hits empty; no monetization or affiliate hits.
  • maintenance_unknown store months_since_update=null; no update date available — scored 0 (no penalty, no credit).

Permissions Breakdown

  • storage low Local key-value store; no cross-origin data access on its own.
  • host_permissions: https://api.indutivacrm.com.br/* medium Scoped to single CRM API domain; enables XHR/fetch to that origin.
  • content_scripts: https://app.indutivacrm.com.br/* low Own CRM app domain — expected for integration.
  • content_scripts: https://web.whatsapp.com/* medium Injects JS into WhatsApp Web; can read messages and DOM data.

Pillar Scores

Permissions1.30
Reputation7.00
Network0.00
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 04:28
Listing SHA 3f3026efb1c7…
Force block — not fired
Score recovered no
Elapsed