Zyntri CRM Conversa
nbenjijhmfecggfipnlkpbplcgnbfgeo
Risk Score
5.38
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Free-webmail dev (gmail), no developer name, no verified publisher — anonymous operator with no accountability.
- Privacy policy is Google's own generic policy — does not scope to this extension; treats as worst-case disclosure.
- cookies permission + content script on web.whatsapp.com enables WhatsApp session token and message interception.
- new Function() constructor + 3 innerHTML DOM-XSS sinks across app.js, background.js, contentScript.js without CSP.
- Small install count (28) with HIGH-tier permissions signals tail-attack-surface risk.
Evidence
- free_webmail_dev_no_name store Developer email thiagoortiz.contato@gmail.com; developer_name empty; no verified publisher badge.
- generic_google_privacy_policy store Privacy URL is myaccount.google.com/privacypolicy — scope_extension=false, data_collection=true, third_party_sharing=true.
- cookies_whatsapp_host manifest cookies permission paired with host_permission and content_script on web.whatsapp.com; session hijack risk.
- code_function_constructor crx new Function() in app.js — dynamic code execution vector without CSP guard.
- code_dom_xss_sinks crx innerHTML DOM-XSS sinks in 3 files (app.js, background.js, contentScript.js); no CSP present.
- no_csp manifest content_security_policy is null; amplifies code-quality risk from innerHTML and Function() findings.
- small_install_high_perm api 28 installs with cookies + tabs + declarativeNetRequest + WhatsApp host — install_perm_anomaly confirmed.
- external_js_hosts crx References notiflix.github.io and reactjs.org as external JS hosts — remote CDN dependency.
Permissions Breakdown
- storage low Local data persistence; low risk on its own.
- unlimitedStorage low Allows large local storage quota; minor concern alone.
- tabs medium Can read tab URLs and metadata across sessions.
- cookies high Can read/write cookies; scoped to declared host but still sensitive.
- notifications low Can display browser notifications; limited risk.
- declarativeNetRequest medium Can block/redirect network requests; less dangerous than webRequest but notable.
- https://web.whatsapp.com/* high Content script and cookie access on WhatsApp — can intercept messages and session tokens.
- https://app.coderlicences.com/* medium Unknown third-party licensing backend; outbound data channel.
Pillar Scores
Permissions5.30
Reputation8.00
Network3.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 11:15
Listing SHA
cb85f6faaa02…
Force block
— not fired
Score recovered
no
Elapsed
—