Afiliado Dash
dfenkhmeopgbbdeidfenplgimikkgchn
Risk Score
5.57
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- cookies+webRequest on MercadoPago (payment) and WhatsApp: can intercept auth tokens and financial session data
- Privacy policy is Google's generic account policy — not scoped to this extension at all; data practices undisclosed
- Brand impersonation: uses WhatsApp brand without confirmed ownership; not verified publisher
- connect.sessiontransfer.com in JS external hosts raises session-hijacking concern — domain name is alarming
- install_url_hijack: onInstalled opens 3rd-party URL; no developer name or email disclosed
Evidence
- cookies+webRequest on payment/auth hosts manifest cookies+webRequest cover auth.mercadopago.com.br and auth.mercadolivre.com.br — session token interception risk.
- connect.sessiontransfer.com in js_external_hosts crx Domain name strongly implies session transfer/hijack functionality; not declared in host_permissions.
- Generic Google privacy policy store privacy_policy_url points to myaccount.google.com; scope_extension=false, data_collection=true, third_party_sharing=true.
- WhatsApp brand impersonation store brand_mention.is_impersonation=true for WhatsApp; confirmed_owner=false, not verified publisher.
- install_url_hijack=true manifest onInstalled opens a 3rd-party URL; target not disclosed.
- No developer identity store developer_name and developer_email are both empty; no accountability signals.
- Privacy policy D-rule trigger store fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → Privacy pillar +10.0.
- scripting+cookies on web.whatsapp.com manifest Extension can inject scripts and read cookies on WhatsApp Web — access to private messages.
Permissions Breakdown
- storage low Local state storage; low risk.
- tabs medium Can read tab URLs and metadata across all tabs.
- activeTab medium Grants temporary access to active tab on user gesture.
- sidePanel low Opens side panel UI; low data-access risk.
- clipboardWrite medium Can write to clipboard; affiliate link injection plausible.
- cookies high Can read/write cookies on declared host_permissions including Mercado Livre and WhatsApp.
- webRequest high Can observe all network requests to declared hosts including auth endpoints.
- scripting medium Can inject scripts into declared host pages.
- alarms low Background scheduling; low standalone risk.
- https://app.afiliadodash.com/* medium Developer-controlled domain; expected for dashboard API.
- https://api.afiliadodash.com/* medium Developer-controlled API endpoint.
- https://mercadolivre.com.br/* high Access to major e-commerce platform including auth; cookies+webRequest combo is high risk.
- https://*.mercadolivre.com.br/* high Broad subdomain access including auth.mercadolivre.com.br.
- https://mercadolivre.com/* high Same as above for .com TLD.
- https://*.mercadolivre.com/* high Broad subdomain coverage on .com TLD.
- https://mercadopago.com.br/* high Payment platform access with cookies+webRequest — critical financial data risk.
- https://*.mercadopago.com.br/* high Broad subdomains of payment platform including auth.
- https://web.whatsapp.com/* high Access to messaging platform; can read conversations via scripting.
Pillar Scores
Permissions7.50
Reputation7.50
Network4.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 11:37
Listing SHA
db410da2f7b9…
Force block
— not fired
Score recovered
no
Elapsed
—