WhatsVoice
ccnllpcenlhbhnkbofajkdlabadcglcd
Risk Score
5.07
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy URL failed to fetch — policy unverifiable, treated as absent (score +10.0).
- Brand impersonation: uses 'whatsapp' brand name with no confirmed ownership, developer on gmail.
- function_constructor (new Function) in bundled JS enables arbitrary code execution paths.
- DOM-XSS sink via innerHTML without CSP to mitigate, amplifying code-quality risk.
- Gmail developer with no verified business identity, no publisher verification, no featured badge.
Evidence
- privacy_policy_fetch_failed api Policy URL https://vmsender.com/privacy-policy.html returned HTTPError; treated as fetched==false → +10.0 privacy.
- brand_impersonation store brand_mention.is_impersonation=true for 'whatsapp'; developer domain is gmail.com, confirmed_owner=false.
- free_webmail_developer store Developer email mkt.robenilson@gmail.com is free webmail; no business website verified.
- function_constructor crx new Function() constructor in whatsvoice_193.js — can execute dynamically constructed code strings.
- dom_sink_innerhtml_userctrl crx innerHTML sink in whatsvoice_12.js; csp_present=false amplifies XSS risk (+2.0 code quality).
- no_csp manifest content_security_policy is null (MV3 strict default applies, no explicit CSP declared).
- js_external_hosts crx 12 distinct external JS hosts including generativelanguage.googleapis.com, socket.io, github.com.
- low_install_count store Only 62 installs; low adoption with no verified publisher increases tail-attack-surface concern.
Permissions Breakdown
- unlimitedStorage low Allows unrestricted local storage; low direct risk but could accumulate data.
- storage low Standard local key-value storage, low risk.
- alarms low Scheduled background execution, low risk alone.
- tabs medium Access to tab URLs and metadata across browser sessions.
- https://web.whatsapp.com/* medium Host access scoped to WhatsApp Web; can read/inject into all WhatsApp sessions.
Pillar Scores
Permissions2.30
Reputation7.50
Network2.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 15:48
Listing SHA
1b37bac8258e…
Force block
— not fired
Score recovered
no
Elapsed
—