Indutiva CRM
ldgfbmnjkfncahaljnceanjaabkbjnca
Risk Score
4.07
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic policy — not scoped to this extension, admits data collection and 3rd-party sharing (Privacy pillar: 10).
- WhatsApp brand mentioned; developer not confirmed owner — impersonation flag raised.
- Content script on web.whatsapp.com can read WhatsApp Web DOM including chat content.
- No developer identity, no install count, no rating — unverifiable provenance.
- DOM-XSS sink (innerHTML) present with no CSP — risk of DOM injection if CRM API returns attacker-controlled content.
Evidence
- privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- brand_impersonation crx brand_mention: whatsapp mentioned, confirmed_owner=false, is_impersonation=true.
- whatsapp_content_script manifest Content script injected into https://web.whatsapp.com/* — reads chat UI and DOM.
- dom_xss_sink crx innerHTML assignment in LoginForm-DbDpxlKu.js; no CSP present (MV3 default strict, but csp_present=false).
- no_developer_identity store developer_name, developer_email, install count, rating all missing — unverifiable.
- external_host_reactjs_org crx js_external_hosts includes reactjs.org — likely redirect/banner URL, not code load.
- no_bad_hosts api threat_intel.bad_host_hits empty; no monetization or affiliate hits.
- maintenance_unknown store months_since_update=null; no update date available — scored 0 (no penalty, no credit).
Permissions Breakdown
- storage low Local key-value store; no cross-origin data access on its own.
- host_permissions: https://api.indutivacrm.com.br/* medium Scoped to single CRM API domain; enables XHR/fetch to that origin.
- content_scripts: https://app.indutivacrm.com.br/* low Own CRM app domain — expected for integration.
- content_scripts: https://web.whatsapp.com/* medium Injects JS into WhatsApp Web; can read messages and DOM data.
Pillar Scores
Permissions1.30
Reputation7.00
Network0.00
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 04:28
Listing SHA
3f3026efb1c7…
Force block
— not fired
Score recovered
no
Elapsed
—