PRAXATECH SOLUÇÕES
bjhbgbfapjofmjcoonncefneakppmkmo
Risk Score
5.41
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's own policy — does not scope to this extension; admits data collection and third-party sharing (Privacy +10.0).
- Operator cluster: 3 sibling extensions under same dev email/host fingerprint suggest coordinated deployment.
- Uninstall URL hijack and install URL hijack both present — classic monetization/tracking shell pattern.
- 10+ distinct external JS hosts under wascript.com.br / watools.com.br contacted by extension running inside WhatsApp Web.
- function_constructor (new Function) + innerHTML DOM-XSS sink detected in 334-file JS bundle with no CSP.
Evidence
- uninstall_url_hijack + install_url_hijack crx Both hijacks set; install redirects to https://web.whatsapp.com. Monetization shell pattern.
- operator_cluster sibling_count=3 api Three sibling extensions share same dev email, install URL, and JS host set — coordinated cluster.
- privacy_policy points to Google's own policy store URL is myaccount.google.com/privacypolicy; scope_extension=false, data_collection=true, third_party_sharing=true.
- js_external_hosts 10+ distinct wascript.com.br subdomains crx api-whatsapp, app, audio-transcriber, backend-plugin, backend-utils, code, meta-oficial, new-multi-atendimento, painel-old all contacted.
- function_constructor in JS bundle crx new Function() constructor found — dynamic code execution risk in 334-file bundle without CSP.
- dom_sink_innerhtml_userctrl crx innerHTML assigned from variable; no CSP present, elevating DOM-XSS risk.
- developer identity weak store Dev name 'wspd'; email contato@extensao.store; not verified publisher, not featured.
- host_permissions scoped to WhatsApp Web manifest Content scripts injected into web.whatsapp.com/* — full access to all WhatsApp messages in browser.
Permissions Breakdown
- unlimitedStorage low Allows unlimited local storage; low direct harm but could store large scraped data.
- storage low Standard local key-value storage; low risk.
- alarms low Enables scheduled tasks; low risk on its own.
- tabs medium Can read tab URLs and titles; moderate privacy surface.
- https://web.whatsapp.com/* medium Scoped host access to WhatsApp Web; content scripts can read all messages on this origin.
Pillar Scores
Permissions2.30
Reputation6.50
Network4.00
Webstore7.50
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure0.00
Operator Siblings (24)
Other extensions sharing this developer's compound fingerprint:
- cellckcnenolgakggljkichbmgmbibgb
- aocojboaoklgedadlpaallelnanhcpgm
- bgnkgembgfkfjipflkniiibgcedloekn
- bpgbjcgkegcecddlnlckjcoddhpmekdh
- cplaeebopfpnoebkaimlibpdickcjofa
- afdhcpnimkgccfjcelgkiipidhebddjh
- abkolnpebgghiglkkdjcgjgbpnddmfmp
- gjlfpggiddcminhebiejofeglfjmleli
- gkkkdobapmhkaihggejlcdbjemfkhdgk
- gollbfedpcfodjgfjddbkfnkkfdedknn
- hcbmcbkjjklkjidikpggmmfpfklcpnmb
- hkdbocoaofpdmbbgpimdkhcafenpkikn
- iibldfhmeiipohbjlkhfgnjhcmkknffi
- ikliliinakofoiojghnipegfphmoljla
- jeicljefnlpdoblklfdephbpihhjgphf
- jkblcpmoooocmdcfjojdecccejlkicap
- jhokpeoaapahcoaigkfnienliabeaang
- jcjodbceolndbhnbljiedcanmglmhmop
- lfenojckeamfnllggndghkmfhkheiimc
- ngnffiapbonmlgijfnlcgbdomhgcmmna
- lhadifphljjldcidjbhdpfcoemhddeec
- hdagfineacponepnaljjkkgjoddgpjld
- dkgcodmnjmlmgmdlbekkcjjjidkflnal
- hpfmfjmhhkfpcedjikogphkfacokfagh
Scoring History
| sssiedne0bc3defdp727562726963xsx | 8.22 | Critical | block | 2026-09-07 |
| v3.6 | 5.41 | Medium | review | 2026-08-28 |
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 10:34
Listing SHA
ec7330265acb…
Force block
— not fired
Score recovered
no
Elapsed
—