Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

WA Blur: Hide Whatsapp™ chats by blurring

mpfonengfdijemalbibanlfjmmhmemdg
Risk Score
5.57
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category PrivacyTool
Installs 5,000
Rating 3.0
Last updated 2024-04-14 (26 months ago)
Manifest version MV3
CSP present ❌ no
Developer labssingularity@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • WhatsApp brand impersonation by unverified gmail developer with no stated org identity.
  • Extension stale for 26 months — zombie risk for compromise or abandonment.
  • Privacy policy is non-scoped (scope_extension=false, data_collection=false) on free GitHub hosting — inadequate.
  • Uninstall URL hijack detected — likely redirects to 3rd-party on uninstall.
  • No CSP on MV3 extension with DOM innerHTML sink in content-script on WhatsApp Web.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true for WhatsApp; developer is gmail user with no confirmed ownership.
  • uninstall_url_hijack crx uninstall_url_hijack=true; 3rd-party redirect on uninstall is a monetization/tracking signal.
  • stale_extension store Last updated April 2024; months_since_update=26, exceeds 24-month high-risk threshold.
  • privacy_policy_inadequate api Policy fetched but scope_extension=false, hosted on free GitHub Pages, length=441 chars.
  • dom_sink_innerhtml crx innerHTML used in content-script.js without CSP; potential DOM-XSS on WhatsApp Web DOM.
  • external_hosts crx js_external_hosts includes fb.me, survey.typeform.com, tally.so — 3 distinct 3rd-party domains.
  • free_webmail_dev_no_org store developer_email=labssingularity@gmail.com; developer_name empty; no verified business entity.
  • verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; partially offsets reputation concerns.

Permissions Breakdown

  • storage low Stores extension settings locally; no cross-site data exposure.
  • host_permission: https://*.web.whatsapp.com/ medium Scoped to WhatsApp Web only; matches stated function but grants DOM access to chat data.

Pillar Scores

Permissions2.00
Reputation7.50
Network3.50
Webstore5.50
Maintenance8.50
Privacy9.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:57
Listing SHA 61fb7a75f44e…
Force block — not fired
Score recovered no
Elapsed 22.0s