WA Sender - Bulk Messages & Automation
cgipcgghboamefelooajpiabilddemlh
Risk Score
5.29
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Critical CVE-2021-23358 (ACE) in bundled underscore@1.8.3 — not patched to fixed_in 1.12.1.
- Privacy policy is the Chrome Web Store listing page itself — no extension-scoped data handling disclosure.
- Free-webmail developer (gmail) with no business identity impersonates WhatsApp brand.
- bit.ly affiliate/cloaking hit in js_external_hosts — short-link redirector with opaque destination.
- new Function() constructor present in both background.js and injected content script; no CSP to mitigate.
Evidence
- critical_cve_bundled_lib crx underscore@1.8.3 carries CVE-2021-23358 (ACE, critical) and CVE-2026-27601 (high DoS); fixed versions available.
- privacy_policy_is_store_listing store privacy_policy_url points to own Chrome Web Store listing page; no scoped policy; scope_extension=false, third_party_sharing=true.
- brand_impersonation store brand_mention.is_impersonation=true for 'whatsapp'; confirmed_owner=false; developer domain is gmail.com.
- free_webmail_dev_no_business store developer_email=luteyguillory8j3@gmail.com; no developer_name; no business domain.
- affiliate_hit_bit_ly crx bit.ly in js_external_hosts — generic short-link redirector flagged as affiliate/cloaking by threat_intel.
- function_constructor_no_csp crx new Function() in background.js and inject-script.js; csp_present=false; no MV3 override mitigation visible.
- uninstall_url_hijack crx uninstall_url_hijack=true; extension registers an uninstall URL (target not resolved).
- high_external_host_count crx 12 distinct js_external_hosts including waplus.io, watools.ai, feross.org beyond core whatsapp.com.
CVE Exposures (9)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23337 | lodash@unknown | high | 4.17.21 | Command Injection in lodash |
| CVE-2026-4800 | lodash@unknown | high | 4.17.21 | Command Injection in lodash |
| CVE-2018-16487 | lodash@unknown | high | 4.17.11 | Prototype Pollution in lodash |
| CVE-2025-13465 | lodash@unknown | moderate | 4.18.0 | lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and |
| CVE-2026-2950 | lodash@unknown | moderate | 4.18.0 | lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and |
| CVE-2018-3721 | lodash@unknown | moderate | 4.17.5 | Prototype Pollution in lodash |
| CVE-2019-10744 | lodash@unknown | critical | 4.17.12 | Prototype Pollution in lodash |
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- storage low Stores extension settings locally; minimal risk.
- alarms low Schedules periodic tasks; low abuse potential.
- *://*.whatsapp.com/* (host) medium Content script on WhatsApp only; scoped but reads chat page DOM.
Pillar Scores
Permissions2.30
Reputation7.50
Network3.50
Webstore6.50
Maintenance0.00
Privacy10.00
Code Quality3.50
CVE Exposure7.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:23
Listing SHA
440ac9c422f8…
Force block
— not fired
Score recovered
no
Elapsed
27.5s