Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Plusfy

pdjlogbgaodpgdlpmikbopjbhabebifb
Risk Score
4.03
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category Productivity
Installs 5
Rating 5.0
Last updated 2025-12-22 (9 months ago)
Manifest version MV3
CSP present ❌ no
Developer Suporte@covertlab.com.br
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Content script on web.whatsapp.com grants full DOM access to WhatsApp messages and contacts.
  • Privacy policy is Google's generic policy — not scoped to this extension; admits data collection and 3rd-party sharing.
  • Uninstall and install URL hijacks detected; install redirects to web.whatsapp.com.
  • WhatsApp brand impersonation by unverified developer — not a Meta-affiliated publisher.
  • Multiple wascript.com.br backend endpoints plus 309 JS files with function_constructor and innerHTML sinks; no CSP.

Evidence

  • content_script_whatsapp manifest content_scripts_matches=[https://web.whatsapp.com/*] — full DOM access to WhatsApp Web including messages.
  • privacy_policy_generic_google store PP URL is myaccount.google.com/privacypolicy — Google's policy, scope_extension=false, data_collection=true, third_party_sharing=true.
  • uninstall_url_hijack crx chrome.runtime.setUninstallURL() present; install_url_hijack opens https://web.whatsapp.com on install.
  • brand_impersonation_whatsapp store brand_mention.is_impersonation=true for WhatsApp; developer domain covertlab.com.br, confirmed_owner=false.
  • external_backend_hosts crx 8 distinct wascript.com.br/waclientes.com.br endpoints plus mail.google.com contacted; no CSP present.
  • function_constructor_no_csp crx new Function() constructor used in content JS with csp_present=false — arbitrary code execution risk.
  • dom_sink_innerhtml_no_csp crx innerHTML assigned from variable in content script; csp_present=false and eval-class finding present → elevated DOM-XSS risk.
  • react_16_13_1_bundled crx React 16.13.1 bundled (below 16.4 threshold noted in rules); no CVEs found in cve_findings_raw.

Permissions Breakdown

  • unlimitedStorage low Can store large amounts of data locally; low sensitivity on its own.
  • storage low Standard local/sync key-value storage; routine.
  • alarms low Allows scheduled callbacks; minimal risk alone.
  • tabs medium Can enumerate tab URLs/titles; combined with WhatsApp content script raises sensitivity.
  • content_scripts_matches: https://web.whatsapp.com/* high Full DOM access on WhatsApp Web — can read messages, contacts, and inject UI.

Pillar Scores

Permissions2.10
Reputation6.00
Network3.50
Webstore7.50
Maintenance3.50
Privacy10.00
Code Quality4.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 05:36
Listing SHA aa2c4305452c…
Force block — not fired
Score recovered no
Elapsed