BC ZAP
ikaghjdimdplapmfhnjnjmepnjnlmpdd
Risk Score
4.36
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Free-webmail developer (gmail) with no verified business identity — high impersonation/abandonment risk.
- WhatsApp brand impersonation: confirmed_owner=false, developer uses gmail, not Meta.
- Content script on web.whatsapp.com can read all chat DOM including message content.
- Privacy policy not scoped to this extension and does not specify data collection; third-party sharing silence adds uncertainty.
- Install URL hijack opens web.whatsapp.com on install; minor but indicative of pattern.
Evidence
- free_webmail_dev store Developer email wl.exten.02@gmail.com is a numbered-alias Gmail; no verified business.
- brand_impersonation store brand_mention.is_impersonation=true for WhatsApp; developer domain is gmail.com, confirmed_owner=false.
- content_script_sensitive_domain manifest Content script injected into https://web.whatsapp.com/* — reads full WhatsApp Web DOM.
- privacy_policy_not_scoped api Privacy policy fetched but scope_extension=false, data_collection=false; generic company policy, not extension-specific.
- install_url_hijack crx install_url_hijack=true; opens https://web.whatsapp.com on install.
- dom_xss_sink crx innerHTML assigned from variable in vendor bundle; no CSP present (MV3 default only).
- no_csp_explicit manifest csp_present=false; MV3 provides default but no explicit extension CSP declared.
- very_low_installs store Only 6 installs; unproven extension with sensitive WhatsApp access and unverified developer.
Permissions Breakdown
- unlimitedStorage low Allows unbounded local storage; no direct data exfil risk alone.
- storage low Standard local key-value storage; low risk.
- tabs medium Can read tab URLs/titles; moderate metadata exposure.
- alarms low Scheduling only; no data access.
- content_scripts:https://web.whatsapp.com/* medium Runs JS in WhatsApp Web context; can read chat content and DOM.
Pillar Scores
Permissions2.10
Reputation7.50
Network1.50
Webstore4.00
Maintenance1.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 04:58
Listing SHA
6c094a072f90…
Force block
— not fired
Score recovered
no
Elapsed
—