WhatsApp Contacts Downloader — Free & Unlimited
fpeeookideimkcgcaodgekbgomnbkdkk
Risk Score
4.75
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- WhatsApp brand impersonation by unverified third-party developer (Quantana/PaperPlanes).
- Privacy policy admits data collection and 3rd-party sharing but is not scoped to this extension — score +10.
- scripting + downloads on web.whatsapp.com allows contact data harvesting and silent file exfil.
- Two additional developer-owned domains (paperplanes.rsvp, paperplanes.quantana.top) in host_permissions with unknown purpose.
- No CSP on MV3 extension with external host access; no code findings to verify benign behavior.
Evidence
- brand_impersonation store WhatsApp brand mentioned; developer domain quantana.com.au is not confirmed owner — is_impersonation=true.
- privacy_policy_generic api Policy fetched (100 KB), scope_extension=false, data_collection=true, third_party_sharing=true — maps to +10 Privacy.
- whatsapp_host_access manifest host_permissions includes https://web.whatsapp.com/* granting full read access to WhatsApp Web session.
- extra_developer_domains manifest paperplanes.rsvp and paperplanes.quantana.top in host_permissions; purpose undisclosed in description.
- no_csp manifest content_security_policy is null; csp_present=false on MV3 extension.
- low_install_scraper store 228 installs; scraper targeting WhatsApp group member data (contacts CSV export).
- downloads_permission manifest downloads permission enables writing arbitrary files to disk, potential data exfil vector.
- unverified_developer store verified_publisher=false, is_featured_by_google=false; no badge to offset reputation risk.
Permissions Breakdown
- scripting medium Can inject JS into whatsapp.com pages — captures contact data in DOM.
- tabs medium Can read URLs/titles of open tabs.
- storage low Local extension data storage; low standalone risk.
- activeTab low Scoped to current tab on user gesture; limited exposure.
- downloads medium Can write files to disk — used for CSV export but also for data exfil.
- https://web.whatsapp.com/* high Full access to WhatsApp Web — can read all messages and contacts.
- https://paperplanes.rsvp/* medium Developer-controlled secondary domain; unknown data flow.
- https://paperplanes.quantana.top/* medium Developer-controlled subdomain; unknown data flow.
Pillar Scores
Permissions3.30
Reputation7.00
Network2.00
Webstore6.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 04:47
Listing SHA
08ae2503312b…
Force block
— not fired
Score recovered
no
Elapsed
—