Zap4Biz: Automação, CRM e Chatbot para WhatsApp Web
gjnkcmipmfefifmlabnljnpcikmngooo
Risk Score
3.55
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Free-webmail Gmail developer with no verified identity — typical throwaway account pattern.
- WhatsApp brand impersonation: developer is not affiliated with Meta/WhatsApp.
- Content script on web.whatsapp.com can read messages; no host_permissions but scoped injection.
- install_url_hijack opens web.whatsapp.com on install — low-severity redirect anomaly.
- DOM-XSS innerHTML sink in vendor bundle with no CSP — elevated XSS risk on WhatsApp Web.
Evidence
- free_webmail_dev store Developer email wl.exten.02@gmail.com — numbered alias Gmail, no business domain.
- brand_impersonation store brand_mention.is_impersonation=true for 'whatsapp'; developer not confirmed owner.
- install_url_hijack manifest install_url_hijack=true; onInstalled opens https://web.whatsapp.com (benign target but anomalous).
- dom_xss_sink_no_csp crx innerHTML sink in vendor.DzFEYc3-.js; csp_present=false — DOM-XSS risk on WhatsApp origin.
- whatsapp_content_script manifest Content script injected into https://web.whatsapp.com/* — can access message DOM.
- external_host_hiperchat crx JS external host hc-stt.hiperchat.com.br — unknown BR domain, possible STT/data relay.
- privacy_policy_third_party api Policy discloses third_party_sharing=true; hosted on opt-api.com not dev-controlled domain.
- very_low_installs store Only 19 installs — very early/experimental; limited blast radius currently.
Permissions Breakdown
- unlimitedStorage low Allows unbounded local storage; low direct harm but can accumulate data.
- storage low Standard key-value storage for extension state.
- tabs medium Can read tab URLs/titles across sessions; moderate surveillance surface.
- alarms low Schedules background tasks; low risk alone.
- content_scripts:https://web.whatsapp.com/* medium Injects JS into WhatsApp Web — can read messages and UI state.
Pillar Scores
Permissions2.30
Reputation7.50
Network1.50
Webstore4.50
Maintenance1.50
Privacy1.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 16:10
Listing SHA
9651ab396792…
Force block
— not fired
Score recovered
no
Elapsed
—