What Vision
ahgellbcclklfinhliakcdgjnebickel
Risk Score
5.40
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic policy — not scoped to this extension; admits data collection and 3rd-party sharing.
- Uninstall and install URL hijack flags set; install redirects to web.whatsapp.com suggesting tracking/onboarding abuse.
- Brand impersonation: uses Google's privacy policy URL and mentions 'google' brand without ownership.
- 10+ external JS hosts under wascript.com.br/watools.com.br loaded from WhatsApp content-script context.
- function_constructor (new Function) and innerHTML DOM-XSS sink found in scanned JS with no CSP protection.
Evidence
- uninstall_url_hijack + install_url_hijack manifest Both uninstall and install URL hijacks flagged; install opens https://web.whatsapp.com on install.
- brand_impersonation store brand_mention: google mentioned, confirmed_owner=false, is_impersonation=true; not verified publisher.
- generic_google_privacy_policy store Privacy URL is myaccount.google.com/privacypolicy — Google's own policy, scope_extension=false, data_collection=true, third_party_sharing=true.
- js_external_hosts crx 10 distinct external hosts under wascript.com.br and watools.com.br contacted from WhatsApp content-script.
- function_constructor crx new Function() constructor found in content JS; enables dynamic code execution.
- dom_sink_innerhtml_userctrl crx innerHTML assigned from variable in content script context; DOM-XSS risk, no CSP present.
- no_csp manifest content_security_policy is null on MV3 extension; amplifies code quality risks.
- low_install_count store Only 233 installs with 10+ external backend hosts; tail attack surface with broad external reach.
Permissions Breakdown
- unlimitedStorage low Allows large local data storage; low direct harm alone.
- storage low Standard extension key-value store; minimal risk.
- alarms low Scheduling API; low risk on its own.
- tabs medium Can read tab URLs and metadata; moderate privacy surface.
- https://web.whatsapp.com/* medium Scoped host access to WhatsApp; reads/writes page DOM including messages.
Pillar Scores
Permissions2.30
Reputation7.00
Network4.00
Webstore8.00
Maintenance0.00
Privacy10.00
Code Quality4.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 09:20
Listing SHA
652c5c5e5e9e…
Force block
— not fired
Score recovered
no
Elapsed
—