WhatsApp AI Agents With CRM Integration | Eazybe
clgficggccelgifppbcaepjdkklfcefd
Risk Score
4.84
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy admits data collection and third-party sharing but is NOT scoped to this extension — worst-case privacy posture.
- <all_urls> host permission paired with scripting enables reading/modifying any page the user visits, including WhatsApp Web.
- AI extension processing WhatsApp messages and CRM data — high-value data exfil surface if compromised.
- Brand impersonation: extension claims WhatsApp association but developer domain eazybe.com is not confirmed owner.
- No developer name listed and no verified-publisher badge despite broad data access and 30K installs.
Evidence
- broad_host_access manifest <all_urls> host permission + scripting allows code injection on every site the user browses.
- privacy_policy_fail api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy score (v3.5 rule D).
- brand_impersonation store brand_mention.is_impersonation=true for WhatsApp; developer eazybe.com is not confirmed owner.
- ai_page_content store AI extension processing WhatsApp chats and CRM data across multiple SaaS platforms.
- no_developer_name store developer_name is empty string; no verified publisher badge.
- featured_by_google store is_featured_by_google=true provides partial reputation credit but does not offset privacy or brand-impersonation risks.
- csp_absent_mv3 manifest csp_present=false on MV3; MV3 has strict default so no Network penalty, but no CSP still noted.
- no_cve_no_obfuscation crx cve_findings_raw empty, obfuscation_score=0.0, code_findings_raw empty — clean code surface.
Permissions Breakdown
- storage low Standard local data persistence; low standalone risk.
- tabs medium Can read URLs and titles of all open tabs.
- alarms low Scheduling only; no data access.
- scripting high Programmatic script injection into pages; elevated when paired with <all_urls>.
- identity low OAuth token retrieval; scoped to user-approved flows.
- identity.email medium Reads user's Google account email address without explicit OAuth scope approval UI.
- <all_urls> (host_permission) high Grants script injection and network interception on every site; broadest possible reach.
Pillar Scores
Permissions6.50
Reputation5.50
Network3.50
Webstore5.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 16:18
Listing SHA
7f9c639528c3…
Force block
— not fired
Score recovered
no
Elapsed
—