Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Super Chat CRM

opocafnnojhngbheikamlpdmijhbobfj
Risk Score
5.14
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 44
Rating 5.0
Last updated 2026-08-25
Manifest version MV3
CSP present ❌ no
Developer superchatcrm@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Cookies permission + WhatsApp host access: full session token and chat data exposure risk.
  • Privacy policy is Google's generic policy — no scope to this extension, admits data collection and 3rd-party sharing.
  • multiple innerHTML DOM-XSS sinks across app.js, background.js, contentScript.js with no CSP.
  • new Function() constructor in app.js is a dynamic code execution risk.
  • Free-webmail dev (gmail) with no developer name or verified business identity.

Evidence

  • cookies + whatsapp host access manifest cookies permission paired with https://web.whatsapp.com/* enables full WhatsApp session/chat read.
  • generic google privacy policy store Policy URL is myaccount.google.com/privacypolicy — not scoped to this extension; admits 3rd-party sharing.
  • function_constructor in app.js crx new Function('return this') dynamic code execution found in app.js.
  • dom_sink_innerhtml_userctrl x3 files, no CSP crx innerHTML sinks in app.js, background.js, contentScript.js with csp_present==false amplify XSS risk.
  • free-webmail dev, no developer name store developer_email=superchatcrm@gmail.com, developer_name empty; no verified business identity.
  • js_external_hosts crx Extension loads from notiflix.github.io and reactjs.org — third-party CDN references in JS.
  • small install + high perm anomaly api Only 44 installs but holds cookies + tabs + WhatsApp host access — tail attack surface.
  • unknown licensing endpoint manifest host_permissions includes https://app.coderlicences.com/* — unverified third-party data endpoint.

Permissions Breakdown

  • storage low Standard local data persistence; low risk.
  • unlimitedStorage low Extends storage quota; low standalone risk.
  • tabs medium Can read tab URLs and metadata across browser sessions.
  • cookies high Can read/write cookies; paired with WhatsApp host access raises session-hijack risk.
  • notifications low Push notifications only; limited risk.
  • declarativeNetRequest medium Can block/redirect network requests; no dynamic rule injection without host access.
  • https://web.whatsapp.com/* high Full access to WhatsApp Web DOM and cookies — chat data, contacts, session tokens.
  • https://app.coderlicences.com/* medium Unknown third-party licensing endpoint; outbound data flows to unverified domain.

Pillar Scores

Permissions5.50
Reputation7.00
Network3.50
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 11:11
Listing SHA 4977e499e58a…
Force block — not fired
Score recovered no
Elapsed