AtendaZap
iibldfhmeiipohbjlkhfgnjhcmkknffi
Risk Score
6.15
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Operator cluster of 14 sibling extensions under same dev email — mass deployment pattern indicating coordinated low-install network.
- Privacy policy is Google's own policy — not scoped to this extension; admits data collection and third-party sharing: +10.0 privacy.
- Uninstall URL hijack and install URL hijack both present — monetization/tracking redirect pattern.
- Brand impersonation flagged (Google mentioned, confirmed_owner=false) with no verified publisher status.
- 10+ distinct external JS hosts under wascript.com.br/watools.com.br — large remote attack surface for a WhatsApp CRM.
Evidence
- operator_cluster_siblings api 13 sibling extensions share same dev email, install URL, and CSP host set — coordinated extension network.
- uninstall_and_install_url_hijack crx uninstall_url_hijack=true and install_url_hijack=true; install redirects to https://web.whatsapp.com.
- privacy_policy_generic_google store Privacy policy points to myaccount.google.com — Google's own policy, not extension-scoped; data_collection+third_party_sharing=true.
- brand_impersonation store brand_mention: Google mentioned, confirmed_owner=false, is_impersonation=true, no verified publisher.
- js_external_hosts crx 12 external JS hosts including api-whatsapp.wascript.com.br, code.wascript.com.br, dev.watools.com.br.
- function_constructor crx new Function() constructor found in v_7_4_3_80_...193.js — dynamic code execution risk.
- dom_sink_innerhtml_userctrl crx innerHTML assignment from variable in v_7_4_3_80_...12.js — DOM-XSS sink with no CSP present.
- no_csp_mv3 manifest csp_present=false on MV3 manifest; innerHTML+function_constructor findings unmitigated.
Permissions Breakdown
- unlimitedStorage low Allows unlimited local storage; low direct harm but enables large data caching.
- storage low Standard local storage access; low risk alone.
- alarms low Allows scheduled tasks; low risk.
- tabs medium Can read tab URLs and titles; moderate risk for session tracking.
- https://web.whatsapp.com/* medium Host access to WhatsApp Web; can read/modify all WhatsApp messages and contacts.
Pillar Scores
Permissions2.30
Reputation8.00
Network5.50
Webstore10.00
Maintenance0.00
Privacy10.00
Code Quality3.50
CVE Exposure0.00
Operator Siblings (24)
Other extensions sharing this developer's compound fingerprint:
- cellckcnenolgakggljkichbmgmbibgb
- aocojboaoklgedadlpaallelnanhcpgm
- bgnkgembgfkfjipflkniiibgcedloekn
- bjhbgbfapjofmjcoonncefneakppmkmo
- bpgbjcgkegcecddlnlckjcoddhpmekdh
- cplaeebopfpnoebkaimlibpdickcjofa
- afdhcpnimkgccfjcelgkiipidhebddjh
- abkolnpebgghiglkkdjcgjgbpnddmfmp
- gjlfpggiddcminhebiejofeglfjmleli
- gkkkdobapmhkaihggejlcdbjemfkhdgk
- gollbfedpcfodjgfjddbkfnkkfdedknn
- hcbmcbkjjklkjidikpggmmfpfklcpnmb
- hkdbocoaofpdmbbgpimdkhcafenpkikn
- ikliliinakofoiojghnipegfphmoljla
- jeicljefnlpdoblklfdephbpihhjgphf
- jkblcpmoooocmdcfjojdecccejlkicap
- jhokpeoaapahcoaigkfnienliabeaang
- jcjodbceolndbhnbljiedcanmglmhmop
- lfenojckeamfnllggndghkmfhkheiimc
- ngnffiapbonmlgijfnlcgbdomhgcmmna
- lhadifphljjldcidjbhdpfcoemhddeec
- hdagfineacponepnaljjkkgjoddgpjld
- dkgcodmnjmlmgmdlbekkcjjjidkflnal
- hpfmfjmhhkfpcedjikogphkfacokfagh
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 14:35
Listing SHA
e2160e2e5fe9…
Force block
— not fired
Score recovered
no
Elapsed
—