Super Chat CRM
opocafnnojhngbheikamlpdmijhbobfj
Risk Score
5.14
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Cookies permission + WhatsApp host access: full session token and chat data exposure risk.
- Privacy policy is Google's generic policy — no scope to this extension, admits data collection and 3rd-party sharing.
- multiple innerHTML DOM-XSS sinks across app.js, background.js, contentScript.js with no CSP.
- new Function() constructor in app.js is a dynamic code execution risk.
- Free-webmail dev (gmail) with no developer name or verified business identity.
Evidence
- cookies + whatsapp host access manifest cookies permission paired with https://web.whatsapp.com/* enables full WhatsApp session/chat read.
- generic google privacy policy store Policy URL is myaccount.google.com/privacypolicy — not scoped to this extension; admits 3rd-party sharing.
- function_constructor in app.js crx new Function('return this') dynamic code execution found in app.js.
- dom_sink_innerhtml_userctrl x3 files, no CSP crx innerHTML sinks in app.js, background.js, contentScript.js with csp_present==false amplify XSS risk.
- free-webmail dev, no developer name store developer_email=superchatcrm@gmail.com, developer_name empty; no verified business identity.
- js_external_hosts crx Extension loads from notiflix.github.io and reactjs.org — third-party CDN references in JS.
- small install + high perm anomaly api Only 44 installs but holds cookies + tabs + WhatsApp host access — tail attack surface.
- unknown licensing endpoint manifest host_permissions includes https://app.coderlicences.com/* — unverified third-party data endpoint.
Permissions Breakdown
- storage low Standard local data persistence; low risk.
- unlimitedStorage low Extends storage quota; low standalone risk.
- tabs medium Can read tab URLs and metadata across browser sessions.
- cookies high Can read/write cookies; paired with WhatsApp host access raises session-hijack risk.
- notifications low Push notifications only; limited risk.
- declarativeNetRequest medium Can block/redirect network requests; no dynamic rule injection without host access.
- https://web.whatsapp.com/* high Full access to WhatsApp Web DOM and cookies — chat data, contacts, session tokens.
- https://app.coderlicences.com/* medium Unknown third-party licensing endpoint; outbound data flows to unverified domain.
Pillar Scores
Permissions5.50
Reputation7.00
Network3.50
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 11:11
Listing SHA
4977e499e58a…
Force block
— not fired
Score recovered
no
Elapsed
—