D2CHATPRO
hdagfineacponepnaljjkkgjoddgpjld
Risk Score
6.29
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Operator cluster of 20 sibling extensions under same dev email — mass distribution shell pattern.
- Privacy policy is Google's own policy — not scoped to this extension; admits data collection and 3rd-party sharing (→ +10 privacy).
- Uninstall URL hijack and install URL hijack both active — traffic-monetization signals.
- WhatsApp brand impersonation by unverified developer (extensao.store).
- 10 external wascript.com.br / watools.com.br hosts contacted; no CSP; new Function() constructor found in code.
Evidence
- operator_cluster_sibling_count_20 api 20 sibling extensions share same dev email, install URL, and CSP host set — mass shell pattern.
- uninstall_and_install_url_hijack crx Both uninstall_url_hijack and install_url_hijack flagged true; install redirects to web.whatsapp.com.
- privacy_policy_google_generic store PP URL is myaccount.google.com/privacypolicy; scope_extension=false, data_collection=true, third_party_sharing=true.
- brand_impersonation_whatsapp store brand_mention.is_impersonation=true for 'whatsapp'; developer not confirmed owner of WhatsApp.
- js_external_hosts_10_domains crx 10 external hosts all under wascript.com.br / watools.com.br; no CSP to constrain them.
- function_constructor_found crx new Function() constructor in content JS; dynamic code execution risk on WhatsApp Web.
- dom_xss_sink_innerhtml crx innerHTML assigned from variable with no CSP; DOM-XSS risk inside WhatsApp Web context.
- no_csp_mv3 manifest csp_present=false; MV3 default CSP applies but external hosts and dynamic eval increase risk.
Permissions Breakdown
- unlimitedStorage low Allows unlimited local storage; low standalone risk for a WhatsApp CRM.
- storage low Standard key-value storage; low risk.
- alarms low Scheduling alarms; benign for CRM reminders.
- tabs medium Can enumerate open tabs and their URLs; moderate privacy surface.
- https://web.whatsapp.com/* medium Host access to WhatsApp Web; enables content script injection into chat sessions.
Pillar Scores
Permissions2.00
Reputation7.00
Network2.00
Webstore10.00
Maintenance0.00
Privacy10.00
Code Quality4.50
CVE Exposure0.00
Operator Siblings (24)
Other extensions sharing this developer's compound fingerprint:
- cellckcnenolgakggljkichbmgmbibgb
- aocojboaoklgedadlpaallelnanhcpgm
- bgnkgembgfkfjipflkniiibgcedloekn
- bjhbgbfapjofmjcoonncefneakppmkmo
- bpgbjcgkegcecddlnlckjcoddhpmekdh
- cplaeebopfpnoebkaimlibpdickcjofa
- afdhcpnimkgccfjcelgkiipidhebddjh
- abkolnpebgghiglkkdjcgjgbpnddmfmp
- gjlfpggiddcminhebiejofeglfjmleli
- gkkkdobapmhkaihggejlcdbjemfkhdgk
- gollbfedpcfodjgfjddbkfnkkfdedknn
- hcbmcbkjjklkjidikpggmmfpfklcpnmb
- hkdbocoaofpdmbbgpimdkhcafenpkikn
- iibldfhmeiipohbjlkhfgnjhcmkknffi
- ikliliinakofoiojghnipegfphmoljla
- jeicljefnlpdoblklfdephbpihhjgphf
- jkblcpmoooocmdcfjojdecccejlkicap
- jhokpeoaapahcoaigkfnienliabeaang
- jcjodbceolndbhnbljiedcanmglmhmop
- lfenojckeamfnllggndghkmfhkheiimc
- ngnffiapbonmlgijfnlcgbdomhgcmmna
- lhadifphljjldcidjbhdpfcoemhddeec
- dkgcodmnjmlmgmdlbekkcjjjidkflnal
- hpfmfjmhhkfpcedjikogphkfacokfagh
Scoring History
| sssiedn5e380074dp727562726963xsx | 6.19 | High | block | 2026-09-07 |
| v3.6 | 6.29 | High | block | 2026-08-31 |
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 15:29
Listing SHA
7ededb0ee0de…
Force block
— not fired
Score recovered
no
Elapsed
—