SevenSales
gmidblfofjdiajmlnfiagijikmojkhia
Risk Score
5.38
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy points to Google's own policy — not scoped to this extension; admits data collection & third-party sharing.
- Uninstall AND install URL hijack flagged; install redirects to web.whatsapp.com suggesting tracking.
- Brand impersonation: extension uses 'WhatsApp' and 'Google' brands without being a confirmed owner.
- 10 distinct external wascript.com.br / watools.com.br API hosts contacted from a 66-install WhatsApp extension.
- new Function() constructor found in content script running inside WhatsApp Web session — arbitrary code exec risk.
Evidence
- privacy_policy_generic_google store Privacy URL is Google's own policy (scope_extension=false, data_collection=true, third_party_sharing=true) — D clause applies: +10.0.
- uninstall_url_hijack + install_url_hijack crx Both onInstalled and uninstall URL hijacks flagged; install_url_target=https://web.whatsapp.com.
- brand_impersonation store brand_mention.is_impersonation=true for WhatsApp and Google; developer is not confirmed owner.
- js_external_hosts crx 10 distinct wascript.com.br/watools.com.br subdomains contacted; >3 distinct registrable domains.
- function_constructor crx new Function() in content script scoped to WhatsApp Web — dynamic code execution risk.
- dom_sink_innerhtml_userctrl crx innerHTML from variable with no CSP present — DOM-XSS sink elevated to +2.0 (csp_present==false).
- no_csp manifest content_security_policy is null (MV3 but csp_present=false); no inline-script protection.
- low_installs_high_external_surface store Only 66 installs but 334 JS files and 10 external API domains — disproportionate backend footprint.
Permissions Breakdown
- unlimitedStorage low Allows unrestricted local storage; low direct harm but can cache large data.
- storage low Standard local key-value storage; minimal risk.
- alarms low Scheduled tasks; low risk, used for CRM reminders.
- tabs medium Can read tab URLs and titles; moderate surveillance surface.
- https://web.whatsapp.com/* medium Host permission scoped to WhatsApp Web; allows content injection into messaging session.
Pillar Scores
Permissions2.30
Reputation7.00
Network3.50
Webstore8.00
Maintenance0.00
Privacy10.00
Code Quality4.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 10:40
Listing SHA
0ad127f082b2…
Force block
— not fired
Score recovered
no
Elapsed
—