ZACRM๐ฆ
opfakiefjdnefefeaacamdpnipefflkp
Risk Score
7.63
Risk Level:
High
Recommendation:
๐ซ BLOCK
Top Risks
- MANAGEMENT PERMISSION: extension can enumerate and disable other installed extensions (incl. security and privacy tools).
- Free-webmail dev (gmail) + <all_urls> + management + scripting: full page/extension control by unverified individual.
- WhatsApp brand impersonation by unverified developer with no confirmed ownership.
- Dynamic script creation + new Function() constructors enable arbitrary code execution at runtime.
- Uninstall URL hijack active; privacy policy fetched but does not scope data collection to this extension.
Evidence
- free_webmail_dev_high_perm manifest Developer email zapautomaticoclick@gmail.com with <all_urls>+management+scripting; no verified publisher.
- brand_impersonation store brand_mention.is_impersonation=true for WhatsApp; developer domain is gmail.com with no confirmed ownership.
- uninstall_url_hijack crx uninstall_url_hijack=true; extension redirects on uninstall to 3rd-party URL.
- small_install_high_perm api Only 20 installs but holds management+scripting+<all_urls>; high tail-attack-surface.
- ai_external_hosts crx Contacts api.openai.com, api.deepseek.com, generativelanguage.googleapis.com, admin.lioncrm.site.
- code_dynamic_exec crx script_src_dynamic in kanban.bundle.js + function_constructor in popup.bundle.js and wasm_license_sw.js.
- privacy_policy_inadequate store Policy fetched but scope_extension=false, data_collection=false, third_party_silence=true; generic non-scoped.
- management_permission manifest management permission allows listing and disabling other installed extensions.
Permissions Breakdown
- storage low Standard local data persistence; low standalone risk.
- tabs medium Can read tab URLs and titles; moderate surveillance risk.
- unlimitedStorage low Allows large local data store; minor risk alone.
- management high Can list/disable/enable other extensions; significant privilege.
- scripting high Programmatic script injection into pages; paired with <all_urls> is critical.
- alarms low Scheduled callbacks only; negligible standalone risk.
- notifications low Display notifications; low risk.
- <all_urls> high Full host access to all sites; combined with scripting enables universal page manipulation.
Pillar Scores
Permissions8.50
Reputation7.50
Network4.00
Webstore7.50
Maintenance0.00
Privacy9.00
Code Quality7.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 04:46
Listing SHA
5d1a895e4940โฆ
Force block
โ not fired
Score recovered
no
Elapsed
โ