Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Wiza - Phone Number & Email Finder

pjmlkdacmaejhkdcflncbpcpidkggoio
Risk Score
4.34
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 100,000
Rating 4.2
Last updated 2026-06-10
Manifest version MV3
CSP present ❌ no
Developer hello@wiza.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but scope_extension=false AND data_collection=true AND third_party_sharing=true → worst-case privacy score (10.0).
  • install_url_hijack=true: onInstalled redirects to linkedin.com/sales/search URL — unsolicited navigation on install.
  • cookies permission combined with scripting on LinkedIn enables harvesting session data and page content at scale.
  • No developer name listed; only email hello@wiza.com; reduces accountability.
  • No CSP (MV3 default enforced, but no explicit policy) and extension handles PII (emails/phones) without scoped disclosure.

Evidence

  • install_url_hijack crx onInstalled opens https://www.linkedin.com/sales/search/people?... — forced navigation on install to LinkedIn Sales Navigator.
  • privacy_policy_not_extension_scoped store Policy at wiza.co/privacy fetched (71207 chars); scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • cookies_permission manifest cookies declared; host scoped to linkedin.com; enables reading auth cookies and session state.
  • no_developer_name store developer_name is empty string; only hello@wiza.com email available, reducing publisher accountability.
  • featured_by_google store is_featured_by_google=true; -2.0 Reputation discount applied (featured badge).
  • no_cve_no_obfuscation crx cve_findings_raw empty, obfuscation_score=0.0, code_findings_raw empty — clean static scan.
  • threat_intel_clean api bad_host_hits, affiliate_hits, monetization_hits all empty; developer domain wiza.com resolves, not throwaway.
  • host_scope_narrow manifest host_permissions and content_scripts limited to https://www.linkedin.com/* only; no broad host access.

Permissions Breakdown

  • cookies high Can read/write cookies; scoped only to linkedin.com via host_permissions but still sensitive.
  • tabs medium Access to tab URLs and metadata; enables tracking browsing within LinkedIn.
  • scripting medium Programmatic script injection; scoped to linkedin.com host_permissions.
  • https://www.linkedin.com/* medium Narrow host scope to LinkedIn only; limits blast radius but still reads page content and cookies.

Pillar Scores

Permissions5.00
Reputation5.50
Network2.00
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:04
Listing SHA 43aa228b81a9…
Force block — not fired
Score recovered no
Elapsed 22.6s