Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

WAPremium MultiWeb

pjlcincdocmbnfjhgbklmagilpmdefdo
Risk Score
4.49
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 2,000
Rating 5.0
Last updated 2026-08-24
Manifest version MV3
CSP present ✅ yes
Developer suporte@multiweb.plus
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy — not scoped to this extension; admits data collection and third-party sharing (Privacy +10).
  • Uninstall and install URL hijack flags set — classic monetization/tracking pattern (Webstore +3).
  • WhatsApp brand impersonation: confirmed_owner=false, is_impersonation=true (Reputation +2).
  • 12 external JS hosts across 4 countries including pay.roote.com.br and painel.wapremium.com.br — broad network surface (Network +1.5).
  • No developer name listed and missing 'Offered by'; verified publisher but no name increases identity opacity (Reputation +1).

Evidence

  • privacy_policy_generic store Policy URL is Google's own account policy (myaccount.google.com); scope_extension=false, data_collection=true, third_party_sharing=true → +10 Privacy (D rule).
  • uninstall_and_install_url_hijack crx Both uninstall_url_hijack and install_url_hijack are true; targets null but pattern is monetization shell (+3 Webstore).
  • brand_impersonation_whatsapp store brand_mention.is_impersonation=true, confirmed_owner=false; WhatsApp brand used without authorization (+2 Reputation).
  • external_hosts_count crx 12 distinct external JS hosts including pay.roote.com.br, painel.wapremium.com.br, socket.io, contate.ai across 4 countries.
  • geo_diversity crx host_geo_diversity country_count=4 (BR, CA, DE, US); category not VPN/Adblock/Translation → +1.5 Network.
  • dom_xss_sink crx innerHTML user-controlled sink in assets/3825.js; CSP present so +0.5 not +2.0 escalation.
  • verified_publisher store verified_publisher=true; -3.0 Reputation but no brand-owner confirmation and no developer name listed.
  • no_developer_name store developer_name is empty string; increases identity opacity (+1.0 Reputation).

Permissions Breakdown

  • storage low Local data persistence; no cross-origin data exposure.
  • tabs medium Can read tab URLs and titles; moderate surveillance potential.
  • content_scripts: https://web.whatsapp.com/* medium Injects JS into WhatsApp Web; can read messages and DOM content.

Pillar Scores

Permissions2.30
Reputation5.50
Network3.50
Webstore7.50
Maintenance0.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 04:46
Listing SHA 30162f6955ee…
Force block — not fired
Score recovered no
Elapsed