InfinyZap
ioimkgpmigbhaddpgmbjjddoaagialah
Risk Score
4.52
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's own policy — not scoped to this extension; admits data collection and third-party sharing.
- Cookie access on WhatsApp Web enables exfiltration of active session tokens.
- No CSP declared (MV3 default only); innerHTML sinks in 3 JS files create DOM-XSS exposure.
- new Function() constructor in app.js enables dynamic code execution.
- Free-webmail dev (gmail), no developer name, 8 installs but holds high-tier permissions — tail attack surface.
Evidence
- privacy_policy_generic store Policy URL is Google's account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 D).
- cookies_on_whatsapp manifest cookies permission + host_permission https://web.whatsapp.com/* — can read WhatsApp session cookies.
- function_constructor crx new Function() in app.js — dynamic code execution risk (+2.5 code quality).
- dom_sink_innerHTML_no_csp crx innerHTML sinks in 3 files with csp_present=false → +2.0 each (FIX B), capped.
- free_webmail_no_devname store Developer email is gmail, developer_name empty → reputation floor 7.5.
- small_install_high_perm api 8 installs but has_high_tier_permission=true, small_install_high_perm=true → +1.5 webstore.
- js_external_hosts crx External JS hosts: notiflix.github.io, reactjs.org — loaded from content scripts context.
- no_csp_mv3 manifest csp_present=false on MV3; no explicit CSP amplifies innerHTML/Function risks.
Permissions Breakdown
- storage low Standard local data storage, low risk.
- unlimitedStorage low Extends storage quota, minimal risk.
- tabs medium Can read tab URLs and metadata.
- cookies high Access to cookies on permitted hosts including WhatsApp session cookies.
- notifications low Can show desktop notifications.
- declarativeNetRequest medium Can block/redirect network requests per static rules.
- https://web.whatsapp.com/* high Full access to WhatsApp Web — can read/modify messages and sessions.
- https://app.coderlicences.com/* medium Contacts unknown third-party license server; data flow opaque.
Pillar Scores
Permissions6.50
Reputation7.50
Network4.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 04:49
Listing SHA
787aeb70d1bf…
Force block
— not fired
Score recovered
no
Elapsed
—