Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Easy Group Contact Extractor for WhatsApp©

ndhmbgnnienbmkefelhnaodahpjgpnnk
Risk Score
4.29
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 60
Rating 5.0
Last updated 2026-05-11 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer yupdash4@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy URL timed out on fetch — effectively no accessible privacy policy; +10.0 privacy pillar.
  • WhatsApp brand impersonation by unaffiliated free-webmail developer (yupdash4@gmail.com); no developer name.
  • Content script on web.whatsapp.com reads contact/chat DOM — high-sensitivity personal data surface with no disclosed data handling.
  • External JS hosts include momentjs.com and techcrunch.com — unexpected for a contact-extractor; suggests remote resource loading risk.
  • Free-webmail developer, no developer name, verified_publisher flag present but dev domain is gmail.com — verification provides little assurance.

Evidence

  • privacy_policy_fetch_failed api privacy_policy_classification.fetched==false; ConnectTimeout on https://wasendbulk.com/privacy-policy/ → +10.0 privacy.
  • brand_impersonation store brand_mention.is_impersonation==true for 'whatsapp'; developer not confirmed owner; dev domain gmail.com.
  • free_webmail_no_dev_name store developer_email=yupdash4@gmail.com; developer_name empty; no business website → reputation floor 7.5.
  • content_script_sensitive_origin manifest Content script injected into https://web.whatsapp.com/* — can access contacts, chats, group member data in DOM.
  • unexpected_external_js_hosts crx js_external_hosts includes momentjs.com and techcrunch.com — techcrunch.com is irrelevant to a WhatsApp extractor.
  • no_csp manifest content_security_policy==null; MV3 strict default applies but external host list raises injection concern.
  • verified_publisher_free_webmail store verified_publisher==true but dev email is gmail.com; 0c cap does not save reputation given free-webmail floor rule.
  • low_install_count store Only 60 installs; minimal blast radius today but permission surface targets sensitive WhatsApp data.

Permissions Breakdown

  • storage low Local key-value storage only; no cross-site data access.
  • tabs medium Can read tab URLs and titles; moderate surveillance surface.
  • content_scripts_matches: https://web.whatsapp.com/* medium Injects JS into WhatsApp Web; can read contacts/chats in DOM.

Pillar Scores

Permissions2.30
Reputation7.50
Network2.50
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 04:58
Listing SHA 31e7b852145a…
Force block — not fired
Score recovered no
Elapsed