Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Pipechat for WhatsApp Web

mbfdhkodejajhcnoljjgkdbdmacahcoc
Risk Score
4.56
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 6,000
Rating 2.9
Last updated 2026-04-09 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@pipechat.app
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Content script injected into WhatsApp Web gives full read access to private messages and contacts.
  • Brand impersonation: extension claims WhatsApp affiliation but developer is not a confirmed WhatsApp owner.
  • Privacy policy fetched but scope_extension==false and admits data collection + third-party sharing — worst policy tier.
  • No developer name listed; low rating (2.9) raises accountability concern.
  • No CSP declared (MV3 mitigates but inline risks remain); policy admits third-party data sharing.

Evidence

  • brand_impersonation store brand_mention.is_impersonation==true for 'whatsapp'; confirmed_owner==false.
  • privacy_policy_admits_collection_and_sharing api fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 rule D).
  • content_script_on_whatsapp manifest content_scripts_matches includes https://web.whatsapp.com/* giving DOM+message access.
  • no_developer_name store developer_name is empty string; +1.0 reputation penalty.
  • low_rating store Rating 2.9 but rating_count not provided; cannot apply >=50 threshold penalty definitively.
  • is_featured_by_google store is_featured_by_google==true; applies -2.0 reputation discount.
  • no_cve_findings crx cve_findings_raw empty; CVE pillar = 0.0.
  • no_code_findings crx code_findings_raw empty, obfuscation_score=0.0; code quality pillar = 0.0.

Permissions Breakdown

  • tabs medium Can read tab URLs and titles; moderate data exposure.
  • storage low Stores extension data locally; low standalone risk.
  • content_scripts@https://web.whatsapp.com/* high Script injection into WhatsApp Web; full access to messages and DOM.
  • content_scripts@https://pdwa.pipechat.app/* medium Script injection into developer's own domain; lower third-party risk.

Pillar Scores

Permissions3.50
Reputation7.00
Network2.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:54
Listing SHA 3161970f3a04…
Force block — not fired
Score recovered no
Elapsed 18.7s