DragonChat - Potencia tu WhatsApp
ieinlppbiopehpocmjjkkemalajklfel
Risk Score
3.36
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy fetched but scope_extension=false and data_collection=false — no meaningful disclosure for this extension.
- WhatsApp brand impersonation flagged; developer is not confirmed owner of WhatsApp brand.
- Two innerHTML DOM-XSS sinks in content scripts running on WhatsApp Web; could process untrusted message content.
- install_url_hijack: onInstall opens dragonchat.io/extension/changelog — low severity but non-standard.
- api.ipify.org contact reveals user IP to third-party service; not disclosed in privacy policy.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true for 'whatsapp'; confirmed_owner=false; verified_publisher=true so +1.0 not +2.0.
- privacy_policy_inadequate api scope_extension=false, data_collection=false, third_party_silence=true → pillar scored at 10.0 per v3 FIX A + +1.0 silence.
- dom_xss_sinks crx 2x dom_sink_innerhtml_userctrl in dc-filters.js and dc-bulk-send.js; csp_present=true so base +0.5 each = +1.0 total.
- install_url_hijack manifest onInstalled opens https://dragonchat.io/extension/changelog?v= — redirects to dev domain, low risk.
- api_ipify_org crx Extension contacts api.ipify.org (IP geolocation third-party); not mentioned in privacy policy.
- no_developer_name store developer_name is empty string; +1.0 reputation penalty applied.
- verified_publisher store verified_publisher=true; -3.0 reputation discount applied (floored at 2.0 per hard floor).
- host_geo_diversity api country_count=2 (CA, US); below threshold of 4, no geo-diversity penalty.
Permissions Breakdown
- activeTab low Grants access only to the currently active tab on user action; limited scope.
- storage low Local extension storage; no cross-origin risk.
- https://web.whatsapp.com/* medium Content-script access to WhatsApp Web; can read messages and DOM.
- https://*.dragonchat.io/* low Scoped to developer's own domain; expected for SaaS backend communication.
Pillar Scores
Permissions1.50
Reputation4.50
Network1.50
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 04:45
Listing SHA
fba788bc10cb…
Force block
— not fired
Score recovered
no
Elapsed
—