bhdkkcffcbililblmbhhgbalkilpgjnn
bhdkkcffcbililblmbhhgbalkilpgjnn
Risk Score
4.64
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Content script on web.whatsapp.com gives full read/write access to WhatsApp messages and session data.
- Uninstall and install URL hijacks both flagged — likely opens third-party pages on install/uninstall.
- Privacy policy is Google's generic account policy, not scoped to this extension; data practices undisclosed.
- No developer identity (no name, no email, no title) — unaccountable publisher.
- No CSP declared (MV3 default applies) combined with innerHTML DOM-XSS sink in bundled library.
Evidence
- content_script_whatsapp manifest content_scripts_matches includes https://web.whatsapp.com/* — full DOM access to WhatsApp Web sessions.
- uninstall_install_url_hijack manifest Both uninstall_url_hijack and install_url_hijack are true; targets are null but flags are set.
- generic_google_privacy_policy store Privacy URL is myaccount.google.com/privacypolicy — Google's own policy, scope_extension=false, data_collection=true.
- no_developer_identity store developer_name, developer_email, and title are all empty strings — publisher is unidentifiable.
- dom_xss_sink crx assets/sweetAlert.js: innerHTML assigned from variable — DOM-XSS risk, no CSP to mitigate.
- no_csp manifest content_security_policy is null; csp_present=false. MV3 default applies but no explicit hardening.
- external_js_hosts crx 12 external JS hosts referenced including tinyurl.com and server.chatsac.com — broad outbound surface.
- privacy_policy_third_party_sharing api Policy admits data_collection=true, third_party_sharing=true but is not scoped to this extension.
Permissions Breakdown
- storage low Stores local extension data; low standalone risk.
- tabs medium Can read tab URLs and metadata; moderate privacy risk.
- content_scripts: https://painel.chatsac.com/* medium Injects scripts into chatsac panel; scoped to dev-controlled domain.
- content_scripts: https://web.whatsapp.com/* high Full script access to WhatsApp Web — can read messages, contacts, sessions.
Pillar Scores
Permissions2.30
Reputation7.50
Network0.00
Webstore8.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 04:51
Listing SHA
fb46dc82417d…
Force block
— not fired
Score recovered
no
Elapsed
—