Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

GD CRM the World’s No.1 WhatsApp CRM for WhatsApp Web

leoaecjkfkmbnapicngpoohkbohmhjki
Risk Score
6.15
Risk Level: High
Recommendation: 🚫 BLOCK
Category AI
Installs
Rating
Last updated
Manifest version MV3
CSP present ❌ no
Developer
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • WhatsApp brand impersonation by unverified developer; no verified publisher badge or developer identity.
  • Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection & 3rd-party sharing.
  • Uninstall and install URL hijack detected; redirects user to WhatsApp Web on install.
  • Content injected into WhatsApp Web with access to 9 host origins including OpenAI, Groq, Anthropic, and wascript.com.br backends.
  • No CSP on MV3 extension with function_constructor and innerHTML DOM-XSS sinks in 309 JS files.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true for 'whatsapp'; developer not confirmed owner.
  • uninstall_url_hijack manifest uninstall_url_hijack=true; install_url_hijack=true targeting https://web.whatsapp.com.
  • generic_privacy_policy store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • no_developer_identity store developer_name, developer_email, and title fields all empty; no verified publisher.
  • broad_ai_backends manifest Host perms include api.openai.com, api.groq.com, api.anthropic.com (js_external_hosts); WhatsApp data sent to AI APIs.
  • function_constructor_code crx new Function() usage in 309-file JS bundle; no CSP; DOM-XSS innerHTML sink also present.
  • no_csp manifest csp_present=false on MV3 extension with code execution sinks.
  • multiple_external_hosts crx 12 distinct external JS hosts including license.geniusdevel.in, wascript.com.br subdomains, vercel.app wildcard.

Permissions Breakdown

  • unlimitedStorage low Local storage expansion; low direct harm potential.
  • storage low Standard key-value storage, low risk.
  • alarms low Scheduling; used for automation tasks, low risk.
  • tabs medium Can read tab URLs and metadata across sessions.
  • *://*.whatsapp.com/* high Full access to WhatsApp Web — reads chats, contacts, messages.
  • *://license.geniusdevel.in/response/gdcrm/* medium License server endpoint; external dependency risk.
  • *://*.vercel.app/* medium Broad Vercel wildcard — any Vercel-hosted app reachable.
  • *://wascript.com.br/* medium Third-party backend; unverified data flows.
  • https://painel.wascript.com.br/* medium Admin panel endpoint; potential data exfiltration surface.
  • https://generativelanguage.googleapis.com/* medium Google Gemini AI API; sends user data to AI provider.
  • https://api.groq.com/* medium Groq AI API; third-party AI provider receives user data.
  • https://api.openai.com/* medium OpenAI API; WhatsApp message content may be forwarded.
  • https://www.gdcrm.store/* medium Developer storefront; unclear what data is sent.

Pillar Scores

Permissions4.30
Reputation8.50
Network5.00
Webstore8.50
Maintenance0.00
Privacy10.00
Code Quality4.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 08:49
Listing SHA 008c61e6b95d…
Force block — not fired
Score recovered no
Elapsed