WANQUEST - CONECTE, AUTOMATIZE E CRESÇA
dfemcgjmfecbgfnabmcafndcjmjiimch
Risk Score
4.57
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is a generic Google URL that failed to fetch — no extension-scoped data handling disclosed.
- WhatsApp impersonation: brand_mention.is_impersonation=true, developer is not a confirmed WhatsApp owner.
- function_constructor (new Function) in content script running inside WhatsApp Web enables arbitrary code execution.
- innerHTML DOM-XSS sink with no CSP in MV3 extension processing WhatsApp messages.
- 12 distinct external JS hosts contacted including generativelanguage.googleapis.com (Gemini AI) and socket.io — broad network surface.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true for 'whatsapp'; developer domain extensao.store not confirmed owner.
- privacy_policy_unfetchable api Privacy policy URL is generic Google account page; fetch failed with SSLError; no extension scope.
- function_constructor_in_content_script crx new Function() found in content script scoped to web.whatsapp.com — dynamic code execution risk.
- dom_xss_sink_no_csp crx innerHTML from variable in content script; csp_present=false amplifies DOM-XSS risk.
- broad_external_hosts crx 12 external JS hosts including generativelanguage.googleapis.com, socket.io, github.com, multiple Google services.
- no_verified_publisher store verified_publisher=false, is_featured_by_google=false; developer 'Intzp' at .store TLD domain.
- very_low_install_count store Only 7 installs; no ratings; minimal community validation for an extension with broad WhatsApp access.
- ai_api_contact crx generativelanguage.googleapis.com in js_external_hosts — extension may send WhatsApp message content to Gemini AI.
Permissions Breakdown
- unlimitedStorage low Allows unbounded local storage; low risk on its own.
- storage low Standard local storage API; low risk.
- alarms low Scheduling alarms; low risk on its own.
- tabs medium Can read tab URLs and titles; moderate risk for CRM context.
- https://web.whatsapp.com/* medium Host permission scoped only to WhatsApp Web; content injection into messaging platform.
Pillar Scores
Permissions2.30
Reputation7.00
Network2.00
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality4.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 15:56
Listing SHA
839d0f696d85…
Force block
— not fired
Score recovered
no
Elapsed
—