Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Nextgo Zap: Seu Whatsapp Turbinado!

pdlpnkplaofpdajmgegfnlifmdlejmfp
Risk Score
5.11
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 438
Rating 5.0
Last updated 2026-08-26
Manifest version MV3
CSP present ❌ no
Developer contato@extensao.store
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's own policy — not scoped to this extension; admits data collection and third-party sharing (Privacy +10.0).
  • Uninstall URL hijack and install URL hijack both flagged; onInstalled redirects to web.whatsapp.com (Webstore +3.0+2.0).
  • WhatsApp brand impersonation by unverified developer 'Intzp' on extensao.store domain (Reputation +2.0).
  • 9 distinct external wascript.com.br/watools.com.br endpoints contacted; broad network surface for a 438-install CRM tool.
  • new Function() constructor found without CSP — dynamic code execution risk on WhatsApp Web content.

Evidence

  • uninstall_url_hijack + install_url_hijack crx Both uninstall and install URL hijacks set; install redirects to https://web.whatsapp.com.
  • generic_privacy_policy store Privacy URL is Google's generic policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0.
  • brand_impersonation store WhatsApp brand mentioned; developer not confirmed owner; is_impersonation=true, unverified publisher.
  • js_external_hosts crx 10 distinct wascript.com.br / watools.com.br subdomains contacted; >3 registrable domains.
  • function_constructor crx new Function() detected in JS bundle without CSP; dynamic code execution risk.
  • dom_sink_innerhtml_userctrl crx innerHTML sink from variable with no CSP present; DOM-XSS risk elevated to +2.0.
  • no_csp crx content_security_policy is null; MV3 default applies but no explicit restriction on eval/remote scripts.
  • developer_identity store Developer 'Intzp' at extensao.store; not verified publisher, not featured, 438 installs.

Permissions Breakdown

  • unlimitedStorage low Local storage expansion; low direct risk but enables large local data caching.
  • storage low Standard extension key-value storage; low risk.
  • alarms low Scheduling alarms; low risk, could enable periodic background tasks.
  • tabs medium Access to tab metadata and URLs; medium risk when combined with host permissions.
  • https://web.whatsapp.com/* medium Scoped host permission to WhatsApp Web; allows full page content read/write on that domain.

Pillar Scores

Permissions1.60
Reputation7.00
Network4.00
Webstore8.00
Maintenance0.00
Privacy10.00
Code Quality4.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 17:05
Listing SHA c55a67ab0a71…
Force block — not fired
Score recovered no
Elapsed