Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Privacy Extension For WhatsApp Web - wabulk.net

mbcghjiodcjankhkllfohcgnckhdbkmi
Risk Score
3.38
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category PrivacyTool
Installs 200,000
Rating 4.7
Last updated 2026-05-23 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@wabulk.net
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: uses 'WhatsApp' brand name without confirmed ownership; is_impersonation=true.
  • Uninstall URL hijack: redirects to privacy-wa-web.wabulk.net/suggestion on removal — monetization/data-harvest signal.
  • Privacy policy URL points to Chrome Web Store listing page, not a real policy; third_party_sharing admitted with no retention disclosed.
  • Content script executes on web.whatsapp.com — direct access to WhatsApp Web DOM including message content.
  • External host ext.leadsext.com contacted — name suggests lead-generation/ad-tech; not in threat_intel but warrants scrutiny.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true for 'whatsapp'; confirmed_owner=false; dev domain wabulk.net unrelated to Meta.
  • uninstall_url_hijack crx uninstall_url_hijack=true; target=https://privacy-wa-web.wabulk.net/suggestion — post-removal redirect.
  • privacy_policy_inadequate store Policy URL resolves to CWS listing page (519KB); scope_extension=true but retention=false, third_party_sharing=true.
  • external_host_leadsext crx js_external_hosts includes ext.leadsext.com — domain name implies lead-generation/ad-tech endpoint.
  • content_script_whatsapp manifest content_scripts_matches=[https://web.whatsapp.com/*]; injects into WhatsApp Web session with message DOM access.
  • no_csp crx csp_present=false on MV3; v2 calibration +2.0 Network penalty applied.
  • verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; mitigates reputation but does not excuse impersonation.
  • no_code_findings crx code_findings_raw=[], obfuscation_score=0.0; no malicious code patterns detected in 10 JS files.

Permissions Breakdown

  • storage low Local key-value storage; no direct data exfil risk.
  • tabs medium Can read tab URLs/titles; moderate surveillance surface.
  • unlimitedStorage low Extends storage quota; low standalone risk.
  • commands low Keyboard shortcut binding; minimal risk.
  • content_scripts:https://web.whatsapp.com/* medium Injects JS into WhatsApp Web; can read messages and DOM.

Pillar Scores

Permissions2.30
Reputation4.50
Network3.50
Webstore6.50
Maintenance0.00
Privacy2.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:54
Listing SHA be93e43d5b13…
Force block — not fired
Score recovered no
Elapsed 23.0s