WA Media Saver
ioeplhdifdmcgooibcibjlaoacbldocc
Risk Score
2.58
Risk Level:
Low
Recommendation:
✅ ALLOW
Top Risks
- Gmail dev email with no verified business identity (free-webmail developer).
- Access to web.whatsapp.com with scripting: can read WhatsApp messages and media.
- Privacy policy admits third_party_sharing but scope is limited; retention not disclosed.
- MV3 + no CSP — mild code injection risk mitigated by narrow host scope.
- Tiny install base (148) limits blast radius but also limits vetting.
Evidence
- developer_email_free_webmail store webservice2t@gmail.com — free webmail, no verified business; +1.5 Reputation.
- host_permission_whatsapp manifest https://web.whatsapp.com/* — access to WhatsApp Web; scripting + downloads combo.
- privacy_policy_third_party_sharing api Policy fetched, scoped, but third_party_sharing=true and retention=false; +1.0 Privacy.
- no_cve_findings crx cve_findings_raw empty; CVE pillar = 0.0.
- code_findings_clean crx code_findings_raw empty, obfuscation_score=0.0; Code Quality = 0.0.
- operator_cluster_singleton api sibling_count=0; no operator cluster penalty.
- justified_broad_discount manifest MediaDownloader category; host access to WhatsApp Web matches stated function; -1.5 Permissions.
- install_count_tiny store Only 148 installs; no install-count boost applied.
Permissions Breakdown
- downloads medium Can save files to disk; expected for media downloader but still a capability risk.
- activeTab low Access to current tab on user action only; limited scope.
- scripting medium Can inject scripts into pages; scoped to web.whatsapp.com only.
- https://web.whatsapp.com/* medium Full access to WhatsApp Web including messages and media; sensitive but narrowly scoped.
Pillar Scores
Permissions2.50
Reputation6.50
Network0.00
Webstore1.50
Maintenance0.00
Privacy2.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 04:51
Listing SHA
85ab639f25ed…
Force block
— not fired
Score recovered
no
Elapsed
—