WaUp
eliddpopegfnapciabpclokjfedpnpij
Risk Score
4.47
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy URL is Google's generic policy (fetch error); no extension-specific data disclosure exists.
- Free-webmail Gmail developer with no verified business identity; unaccountable if extension is sold.
- eval() in bundled audio encoder libs with no CSP; remote-code-execution surface if libs are compromised.
- External JS host 'discoveric.ru' (Russia-geolocated) alongside 3 distinct country origins raises supply-chain concern.
- Content script on web.whatsapp.com can read message DOM; combined with third-party backend API (prontei.com), message data could be exfiltrated.
Evidence
- free_webmail_developer store Developer email hebrainmartins@gmail.com — free webmail, no verified business domain.
- privacy_policy_fetch_failed api Privacy policy URL points to Google's generic policy; fetch returned SSLError — no extension-scoped policy.
- eval_in_bundled_libs crx eval() found in Mp3LameEncoder.min.js and OggVorbisEncoder.min.js; no CSP to mitigate.
- function_constructor crx new Function() in sweetalert2.js can execute arbitrary strings; no CSP present.
- suspicious_external_host crx JS contacts discoveric.ru (RU-geolocated); unrecognized host for a WhatsApp productivity tool.
- third_party_backend manifest host_permission for app.prontei.com/api/* — data from WhatsApp DOM could be sent to unknown backend.
- no_csp manifest content_security_policy is null; eval and Function() findings have no mitigating CSP barrier.
- geo_diversity api JS hosts span 3 countries (CA, RU, US); Russian-hosted endpoint is anomalous for this category.
Permissions Breakdown
- storage low Local data persistence; low harm potential alone.
- unlimitedStorage low Extends storage quota; no direct data-exfil risk.
- activeTab low Scoped to user-activated tab; limited reach.
- host: https://web.whatsapp.com/* medium Content script on WhatsApp; can read messages and DOM.
- host: https://app.prontei.com/api/* medium Allows XHR to third-party backend; data could be sent there.
Pillar Scores
Permissions1.00
Reputation7.50
Network3.50
Webstore2.50
Maintenance3.50
Privacy10.00
Code Quality3.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 16:23
Listing SHA
89860d4eed40…
Force block
— not fired
Score recovered
no
Elapsed
—