WhatsApp™ Number Generator & Checker - ExtBoost
ipbgdicbhbblkaabpgkhkhebjjfdcbah
Risk Score
4.90
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- WhatsApp brand impersonation by unverified free-webmail developer (exportmyinfohq@gmail.com) with no developer name.
- Content script on <all_urls> + https://*.whatsapp.com/* exposes all browsing and WhatsApp session/messages.
- identity + identity.email permissions allow silent Google account email harvest.
- Privacy policy admits third-party data sharing without scoping to this extension; no retention period disclosed.
- Small-install (102) high-permission anomaly signals possible targeted or experimental exfil tool.
Evidence
- brand_impersonation store Title uses WhatsApp™ trademark; developer domain is gmail.com, confirmed_owner=false, is_impersonation=true.
- free_webmail_no_dev_name store developer_email=exportmyinfohq@gmail.com, developer_name empty; no verified business identity.
- broad_host_access manifest host_permissions=[https://*/*] + content_scripts on <all_urls> grants universal page access.
- whatsapp_content_script manifest Dedicated content script on https://*.whatsapp.com/* can read messages, contacts, session tokens.
- identity_email_permission manifest identity + identity.email can silently retrieve signed-in Google account email via OAuth.
- dom_xss_sinks crx 3 innerHTML-from-variable sinks found; no CSP present (csp_present=false), elevating XSS risk.
- privacy_policy_third_party_sharing api Policy fetched: scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
- small_install_high_perm_anomaly store 102 installs with HIGH-tier permissions; install_perm_anomaly.small_install_high_perm=true.
Permissions Breakdown
- storage low Local state persistence; low standalone risk.
- identity medium Can obtain OAuth tokens; risk amplified by gmail-only dev identity.
- identity.email medium Reads signed-in Google account email; PII exfil surface.
- https://*/* high Broad host access across all HTTPS sites; HIGH tier.
- <all_urls> (content_script) high Content script injected on all URLs, reads/modifies any page DOM.
- https://*.whatsapp.com/* (content_script) high Direct access to WhatsApp session data, messages, contacts.
Pillar Scores
Permissions6.50
Reputation7.50
Network2.00
Webstore7.00
Maintenance0.00
Privacy2.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 16:13
Listing SHA
2b5d5e799ec7…
Force block
— not fired
Score recovered
no
Elapsed
—