WhatSender PRO - WhatsApp Bulk Sender
cpficbpjnbekidkijhpbofgncpfolmeb
Risk Score
4.43
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and third-party sharing.
- Brand impersonation: extension uses 'WhatsApp' brand name; developer is unverified gmail user with no confirmed ownership.
- Bundled jQuery 3.4.1 has two medium-severity XSS CVEs (CVE-2020-11022, CVE-2020-11023); no CSP to mitigate.
- DOM-XSS sink (innerHTML) in content.js combined with no CSP and vulnerable jQuery amplifies XSS risk on WhatsApp domain.
- Free-webmail developer (tuttoemailsoft@gmail.com), no developer name, no verified publisher — minimal accountability.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; developer gmail.com not confirmed WhatsApp owner.
- generic_privacy_policy store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- cve_jquery_xss crx jQuery 3.4.1 bundled; CVE-2020-11022 and CVE-2020-11023 (medium severity); fixed_in 3.5.0.
- dom_sink_no_csp crx innerHTML sink in content.js with csp_present=false and vulnerable jQuery; elevated XSS risk.
- free_webmail_dev_no_name store Developer email tuttoemailsoft@gmail.com; developer_name empty; no verified publisher badge.
- install_url_hijack manifest install_url_hijack=true; onInstalled opens https://web.whatsapp.com (same domain as stated function).
- privacy_policy_d_clause store scope_extension=false AND data_collection=true AND third_party_sharing=true → Privacy pillar +10.0 (v3.5 D).
- cve_amplifier_no_csp_jquery crx No CSP + DOM-manipulation lib with medium CVEs triggers v2 ×1.5 CVE amplifier; cve_pillar=4.5.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2020-11022 | jquery@3.4.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.4.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- tabs medium Can read tab URLs/titles; moderate risk for session awareness.
- storage low Local extension data storage; low standalone risk.
- activeTab low Scoped to user-clicked tab only; low risk.
- sidePanel low UI panel display; no data-access risk.
- *://*.whatsapp.com/* medium Content-script and host access scoped to WhatsApp only; matches stated function.
Pillar Scores
Permissions2.30
Reputation8.50
Network0.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality2.50
CVE Exposure4.50
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 04:48
Listing SHA
eae81d728e69…
Force block
— not fired
Score recovered
no
Elapsed
—