WhatsApp™ Scraper & Bulk Sender & Auto Join - ExtBoost
gbfehnilmikecbbenafhoceeckfpoojh
Risk Score
5.49
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- Explicit scraper+bulk-sender for WhatsApp with broad <all_urls> host access — high exfil and spam potential.
- WhatsApp brand impersonation by unverified gmail developer with no developer name disclosed.
- Privacy policy admits third-party data sharing but lacks retention disclosure; data collection confirmed.
- 3 innerHTML DOM-XSS sinks with no CSP present amplify code-quality risk on injected content.
- Small install count (280) with HIGH-tier permissions is tail-attack-surface anomaly.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; developer is gmail-hosted, not WhatsApp/Meta.
- broad_host_access manifest host_permissions https://*/* + content_scripts <all_urls>; scraper function maps to every HTTPS site.
- free_webmail_dev_no_name store developer_email=exportmyinfohq@gmail.com, developer_name empty; no business identity verifiable.
- small_install_high_perm api install_perm_anomaly.small_install_high_perm=true; 280 installs with HIGH-tier host permissions.
- privacy_third_party_sharing crx Policy fetched; scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
- dom_xss_no_csp crx 3 innerHTML sinks across 3 JS files; csp_present=false amplifies XSS risk per FIX B.
- external_js_host crx js_external_hosts includes api.ext-api.com and web.whatsapp.com; outbound API contact confirmed.
- tos_violation_scraper store Extension explicitly states WhatsApp scraping + bulk sending — ToS violation of WhatsApp/Meta platform.
Permissions Breakdown
- storage low Local data persistence only; low standalone risk.
- identity medium Can access Google account identity tokens; combined with scraper function raises risk.
- identity.email medium Reads signed-in user email; unnecessary for stated bulk-messaging purpose.
- https://*/* high Broad host access across all HTTPS sites; enables cross-site data collection.
- content_scripts: <all_urls> high Content scripts injected on all URLs; combined with scraper function is high exfil surface.
Pillar Scores
Permissions7.50
Reputation7.00
Network2.00
Webstore7.50
Maintenance0.00
Privacy2.00
Code Quality4.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 16:13
Listing SHA
d5d4e7049f55…
Force block
— not fired
Score recovered
no
Elapsed
—