WaBest
ghajfmiecdhdkifpapbjngmcdbedjmgg
Risk Score
5.45
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's own policy (not scoped to this extension) — admits data collection and 3rd-party sharing: scores +10.0.
- Uninstall URL hijack and install URL hijack both flagged — aggressive lifecycle interception.
- WhatsApp brand impersonation by unverified developer 'wty' on throwaway-pattern domain.
- 10 external JS hosts (wascript.com.br, watools.com.br) contacted at runtime with no CSP — remote code loading surface.
- function_constructor (new Function) in bundled JS combined with no CSP raises XSS/code-injection risk.
Evidence
- privacy_policy_generic_google store Privacy URL points to Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
- uninstall_and_install_url_hijack crx uninstall_url_hijack=true and install_url_hijack=true; install target=https://web.whatsapp.com — lifecycle interception +3.0+2.0 webstore.
- brand_impersonation_whatsapp store brand_mention.is_impersonation=true, confirmed_owner=false, developer not verified → +2.0 reputation.
- js_external_hosts_count crx 10 distinct external hosts under wascript.com.br/watools.com.br; >3 distinct registrable domains → +1.5 network.
- no_csp_mv3 manifest csp_present=false on MV3; dom_sink_innerhtml_userctrl present → FIX B applies, dom_sink scored at +2.0 code quality.
- function_constructor_finding crx new Function() constructor detected → +2.5 code quality (debugger_attach/function_constructor tier).
- developer_identity_weak store Developer name 'wty' is opaque; email on extensao.store TLD; not verified publisher, not featured → reputation base elevated.
- install_count_low_with_high_external_surface store Only 835 installs but 334 JS files and 10 external hosts — large attack surface relative to user base.
Permissions Breakdown
- unlimitedStorage low Allows storing large data locally; low direct harm potential.
- storage low Standard local key-value storage, minimal risk.
- alarms low Scheduling alarms; low risk in isolation.
- tabs medium Can read tab URLs and titles across sessions; moderate privacy risk.
- https://web.whatsapp.com/* (host) medium Content script on WhatsApp Web; can read all chat data on that domain.
Pillar Scores
Permissions2.30
Reputation6.00
Network4.00
Webstore8.50
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 10:10
Listing SHA
32e5e00fe1c5…
Force block
— not fired
Score recovered
no
Elapsed
—