ChatzyCRM: Todo lo que necesitas en un solo CRM para WhatsApp
bpjhhjboiagpamldnmjdmjadhajipicf
Risk Score
5.38
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Content script injected into WhatsApp Web can read all messages and user data with no CSP protection.
- Privacy policy is Google's generic policy — does not scope to this extension; admits data collection and third-party sharing (D rule: +10).
- WhatsApp brand impersonation by unverified developer (nexcorp.pe).
- Uninstall URL hijack and install URL hijack both present — monetization/tracking shell signals.
- 12 distinct external JS hosts including multiple wascript.com.br and watidy.com domains with no CSP.
Evidence
- content_script_whatsapp manifest Content script on https://web.whatsapp.com/* with no CSP — full DOM/message access.
- privacy_policy_generic_google store Privacy URL is myaccount.google.com/privacypolicy — Google's own policy, not scoped to this extension.
- brand_impersonation_whatsapp store brand_mention.is_impersonation=true; developer nexcorp.pe is not confirmed WhatsApp owner.
- url_hijack_both crx uninstall_url_hijack=true AND install_url_hijack=true; install target https://web.whatsapp.com.
- external_hosts_count crx 12 js_external_hosts including wascript.com.br (x4), watidy.com, wabacrm.store, glexmedia.in.
- no_csp manifest content_security_policy is null/absent on MV3 extension with remote host dependencies.
- function_constructor crx new Function() constructor found in bundled JS — dynamic code execution risk.
- privacy_policy_admits_third_party api policy: scope_extension=false, data_collection=true, third_party_sharing=true — triggers D rule max score.
Permissions Breakdown
- unlimitedStorage low Allows unlimited local storage; low direct harm.
- storage low Standard local key-value storage access.
- alarms low Scheduling API; low risk on its own.
- tabs medium Can read tab URLs and metadata across all tabs.
- declarativeNetRequest medium Can redirect/block network requests declaratively.
- *://*.glexmedia.in/* medium Host access to third-party domain of unclear ownership.
- *://*.wabacrm.store/* medium Host access to developer-adjacent CRM backend domain.
- *://chatzycrm.com/* medium Host access to extension's own backend domain.
- content_scripts: https://web.whatsapp.com/* high Injects JS into WhatsApp Web; can read all messages and DOM.
Pillar Scores
Permissions2.60
Reputation6.50
Network4.00
Webstore7.50
Maintenance3.50
Privacy10.00
Code Quality2.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 08:04
Listing SHA
17755e93db82…
Force block
— not fired
Score recovered
no
Elapsed
—