Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Zyntri CRM Conversa

nbenjijhmfecggfipnlkpbplcgnbfgeo
Risk Score
5.38
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 28
Rating
Last updated 2026-08-25
Manifest version MV3
CSP present ❌ no
Developer thiagoortiz.contato@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Free-webmail dev (gmail), no developer name, no verified publisher — anonymous operator with no accountability.
  • Privacy policy is Google's own generic policy — does not scope to this extension; treats as worst-case disclosure.
  • cookies permission + content script on web.whatsapp.com enables WhatsApp session token and message interception.
  • new Function() constructor + 3 innerHTML DOM-XSS sinks across app.js, background.js, contentScript.js without CSP.
  • Small install count (28) with HIGH-tier permissions signals tail-attack-surface risk.

Evidence

  • free_webmail_dev_no_name store Developer email thiagoortiz.contato@gmail.com; developer_name empty; no verified publisher badge.
  • generic_google_privacy_policy store Privacy URL is myaccount.google.com/privacypolicy — scope_extension=false, data_collection=true, third_party_sharing=true.
  • cookies_whatsapp_host manifest cookies permission paired with host_permission and content_script on web.whatsapp.com; session hijack risk.
  • code_function_constructor crx new Function() in app.js — dynamic code execution vector without CSP guard.
  • code_dom_xss_sinks crx innerHTML DOM-XSS sinks in 3 files (app.js, background.js, contentScript.js); no CSP present.
  • no_csp manifest content_security_policy is null; amplifies code-quality risk from innerHTML and Function() findings.
  • small_install_high_perm api 28 installs with cookies + tabs + declarativeNetRequest + WhatsApp host — install_perm_anomaly confirmed.
  • external_js_hosts crx References notiflix.github.io and reactjs.org as external JS hosts — remote CDN dependency.

Permissions Breakdown

  • storage low Local data persistence; low risk on its own.
  • unlimitedStorage low Allows large local storage quota; minor concern alone.
  • tabs medium Can read tab URLs and metadata across sessions.
  • cookies high Can read/write cookies; scoped to declared host but still sensitive.
  • notifications low Can display browser notifications; limited risk.
  • declarativeNetRequest medium Can block/redirect network requests; less dangerous than webRequest but notable.
  • https://web.whatsapp.com/* high Content script and cookie access on WhatsApp — can intercept messages and session tokens.
  • https://app.coderlicences.com/* medium Unknown third-party licensing backend; outbound data channel.

Pillar Scores

Permissions5.30
Reputation8.00
Network3.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 11:15
Listing SHA cb85f6faaa02…
Force block — not fired
Score recovered no
Elapsed