autozai – Otimize o tempo e multiplique as vendas no WhatsApp
hknmlgmbiononigjnihhflhmmmhfbjpl
Risk Score
6.35
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- Privacy policy is Google's own policy — not scoped to this extension; admits data collection and 3rd-party sharing (score +10).
- Uninstall URL hijack and install URL hijack both flagged; classic monetization/tracking shell behavior (+3 Webstore each).
- WhatsApp brand impersonation by unverified developer with no confirmed ownership (+2 Reputation).
- 10 distinct external wascript.com.br/watools.com.br endpoints contacted; broad backend surface with no CSP (network risk +2).
- function_constructor (new Function()) in content script + innerHTML sink with no CSP raises DOM-XSS / code-injection risk.
Evidence
- uninstall_url_hijack + install_url_hijack manifest Both onInstalled and onUninstalled URL hooks set; classic monetization shell pattern.
- privacy_policy_generic_google store Privacy policy URL is myaccount.google.com — Google's own policy, not scoped to this extension; data_collection+third_party_sharing true.
- brand_impersonation_whatsapp store brand_mention.is_impersonation=true for WhatsApp; developer domain extensao.store not confirmed owner.
- external_hosts_broad crx 10 distinct wascript.com.br/watools.com.br subdomains in js_external_hosts; no CSP to restrict outbound connections.
- function_constructor crx new Function() detected in content script — code-injection risk (+2.5 code quality).
- dom_sink_innerhtml_userctrl crx innerHTML sink with no CSP present — elevated DOM-XSS risk (+2.0 per FIX B).
- no_csp_mv3 manifest content_security_policy is null; MV3 default applies but external host connections remain unrestricted.
- unverified_developer store verified_publisher=false, not featured, developer name 'Stfl' minimal, dev email on extensao.store domain.
Permissions Breakdown
- unlimitedStorage low Allows large local storage; low risk for a CRM tool.
- storage low Standard key-value storage; expected for CRM state.
- alarms low Scheduling alarms; low risk.
- tabs medium Can read tab URLs and titles; moderate risk when paired with WhatsApp host access.
- https://web.whatsapp.com/* medium Scoped to WhatsApp Web only; matches stated function but grants full page-script access to chat data.
Pillar Scores
Permissions2.30
Reputation7.50
Network4.50
Webstore8.00
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 10:46
Listing SHA
3a45c2ba7af9…
Force block
— not fired
Score recovered
no
Elapsed
—