WA Envio
dfcngbjlmlakepppfaaepideejcbfcjf
Risk Score
5.53
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Uninstall URL hijack + install URL hijack detected — classic monetization/tracking shell pattern.
- Privacy policy is Google's own policy (generic, unscoped) but admits data collection and 3rd-party sharing — Privacy pillar scores 10.
- WhatsApp brand impersonation by unverified developer 'wty' via extensao.store domain.
- 10 external JS hosts under wascript.com.br/watools.com.br contacted at runtime — large unverified backend surface.
- function_constructor (new Function) combined with no CSP and innerHTML DOM-XSS sink raises code quality risk.
Evidence
- install_url_hijack + uninstall_url_hijack crx Both onInstalled and uninstall URL hooks present; install redirects to https://web.whatsapp.com — monetization/tracking pattern.
- generic_privacy_policy store Policy URL is Google's own privacy page; scope_extension=false, data_collection=true, third_party_sharing=true — Privacy pillar=10.
- brand_impersonation store WhatsApp brand mentioned; developer not confirmed owner of brand; is_impersonation=true, not verified/featured.
- large_external_host_surface crx 10 distinct wascript.com.br/watools.com.br endpoints in js_external_hosts — broad unverified backend.
- function_constructor crx new Function() constructor found in bundled JS; no CSP present (MV3 but csp_present=false).
- dom_sink_innerhtml_userctrl crx innerHTML assigned from variable; no CSP and eval-like finding present → elevated DOM-XSS risk (FIX B applies).
- unverified_developer store Developer name 'wty', email contato@extensao.store; no verified publisher badge, no Google featured badge.
- no_csp manifest content_security_policy is null; csp_present=false on MV3 extension with external hosts and code findings.
Permissions Breakdown
- unlimitedStorage low Allows large local data storage; low direct harm but could cache sensitive data.
- storage low Standard key-value local storage; low risk.
- alarms low Schedule periodic tasks; low risk standalone.
- tabs medium Can read tab URLs and titles; moderate risk for browsing history exposure.
- https://web.whatsapp.com/* medium Host permission scoped to WhatsApp Web; allows content script injection and data access on that domain.
Pillar Scores
Permissions2.30
Reputation6.50
Network3.50
Webstore8.50
Maintenance0.00
Privacy10.00
Code Quality4.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 09:48
Listing SHA
76d202a1bb56…
Force block
— not fired
Score recovered
no
Elapsed
—