Easy Wapi - Api fácil para WhatsApp
hoeeojgceocplocgolojeblocambibnn
Risk Score
5.14
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Abandoned extension (30 months since update) running on WhatsApp Web with no patch cadence.
- Privacy policy is Google's generic policy — does not scope data handling to this extension at all.
- WhatsApp brand impersonation by unverified gmail developer with no business domain.
- DOM-XSS sink (innerHTML) in content script injected into WhatsApp Web with no CSP protection.
- Free-webmail developer identity, unverifiable accountability, no verified publisher status.
Evidence
- maintenance_stale store Last updated February 2024; 30 months since update — zombie extension on active communication platform.
- privacy_policy_generic store Policy URL points to Google account privacy page — scope_extension=false, data_collection=true, third_party_sharing=true.
- brand_impersonation store brand_mention.is_impersonation=true for 'whatsapp'; developer domain is gmail.com, confirmed_owner=false.
- dom_xss_sink crx innerHTML assigned from variable in main JS bundle; no CSP present (csp_present=false) amplifies risk.
- free_webmail_dev store Developer email cardosodev.contact@gmail.com — gmail, no business domain, unverified publisher.
- content_script_whatsapp manifest Content script on https://web.whatsapp.com/* — can access WhatsApp session, messages, contacts.
- react_v16 crx React 16.13.1 bundled — below 16.4 threshold; no CSP present, triggering v2 CVE amplifier risk surface.
- low_install_count store Only 88 installs; rating 3.0 with minimal adoption — limited blast radius but unvetted quality.
Permissions Breakdown
- content_scripts: https://web.whatsapp.com/* medium Runs JS on WhatsApp Web — can read/modify chat content; narrow host scope limits blast radius.
Pillar Scores
Permissions0.30
Reputation7.50
Network0.00
Webstore4.00
Maintenance8.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 04:54
Listing SHA
bcd8b084850b…
Force block
— not fired
Score recovered
no
Elapsed
—