Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Crm Grátis

ljdglkbjbimcfogoknmggdcjlnddamil
Risk Score
5.33
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 3
Rating
Last updated 2026-05-14 (4 months ago)
Manifest version MV3
CSP present ❌ no
Developer coderlicences@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Cookie access on WhatsApp Web enables session hijacking and message interception.
  • Privacy policy is Google's generic policy — does not scope to this extension or disclose collection.
  • Free-webmail developer (gmail), no verified publisher, 3 installs — high tail-attack-surface risk.
  • new Function() constructor and multiple innerHTML DOM-XSS sinks in content/background scripts.
  • No CSP declared (MV3 mitigates partially) but DOM sinks + no CSP amplifies XSS risk.

Evidence

  • cookies + WhatsApp host access manifest cookies permission paired with https://web.whatsapp.com/* enables reading WhatsApp session cookies.
  • generic Google privacy policy store Privacy URL points to myaccount.google.com/privacypolicy — not scoped to this extension; data_collection=true, third_party_sharing=true.
  • free-webmail developer, no verified publisher store Developer email coderlicences@gmail.com; verified_publisher=false; is_featured=false; 3 installs.
  • new Function() constructor in app.js crx function_constructor signal found; dynamic code execution risk in content context.
  • innerHTML DOM-XSS sinks (3 files) crx dom_sink_innerhtml_userctrl in app.js, background.js, contentScript.js; no CSP to mitigate.
  • install_perm_anomaly api small_install_high_perm=true; 3 installs with cookies + tabs + declarativeNetRequest + WhatsApp host.
  • external JS hosts manifest js_external_hosts: notiflix.github.io, reactjs.org — remote CDN references in extension context.
  • wayback ownership check api Wayback fetch error; no ownership-change confirmed but dev domain not verifiable via CT logs (free webmail).

Permissions Breakdown

  • storage low Standard local data storage; low risk.
  • unlimitedStorage low Allows large local storage; minor risk.
  • tabs medium Can read tab URLs and metadata across browser.
  • cookies high Can read/write cookies; combined with host access to WhatsApp this is elevated risk.
  • notifications low Can show notifications; nuisance risk only.
  • declarativeNetRequest medium Can block/redirect network requests; moderate risk.
  • https://web.whatsapp.com/* high Full access to WhatsApp Web including messages; high sensitivity.
  • https://app.coderlicences.com/* medium Dev-controlled backend; data exfil surface.

Pillar Scores

Permissions5.00
Reputation7.50
Network2.00
Webstore5.50
Maintenance1.50
Privacy10.00
Code Quality5.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-15 13:05
Listing SHA c5ba899a0e73…
Force block — not fired
Score recovered no
Elapsed