PharmaZap
jbjpfhemoolhegecihahbkfhaohohacd
Risk Score
6.54
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- cookies permission + WhatsApp host access enables WhatsApp session cookie theft/exfil.
- Privacy policy is Google's own policy — not scoped to this extension; admits data collection + 3rd-party sharing.
- Free Gmail dev email, no dev name, no verified publisher — low accountability.
- function_constructor + multiple innerHTML DOM-XSS sinks with no CSP elevate code-execution risk.
- Low install count (49) with high-tier permissions is a tail-attack-surface anomaly.
Evidence
- cookies+WhatsApp host manifest cookies permission paired with https://web.whatsapp.com/* enables full session cookie access to WhatsApp Web.
- generic privacy policy store Privacy URL is Google's own policy (myaccount.google.com); scope_extension=false, data_collection=true, third_party_sharing=true.
- free webmail dev, no name store Developer email christian.pharmapro@gmail.com; developer_name empty; no verified publisher badge.
- function_constructor in app.js crx new Function() call detected in app.js — dynamic code execution risk.
- 3x innerHTML DOM-XSS sinks crx innerHTML assigned from variables in app.js, background.js, contentScript.js with no CSP present.
- no CSP manifest content_security_policy is null/absent; amplifies all code-quality findings.
- unknown licensing endpoint manifest https://app.coderlicences.com/* in host_permissions — unverified third-party domain.
- install_perm_anomaly api 49 installs with high-tier permissions (cookies, tabs); small_install_high_perm=true.
Permissions Breakdown
- storage low Persists local extension data; low risk.
- unlimitedStorage low Removes storage quota; low standalone risk.
- tabs medium Can read tab URLs and metadata across browser.
- cookies high Can read/write cookies; combined with host perms on WhatsApp is session-theft risk.
- notifications low Can push desktop notifications; low risk.
- declarativeNetRequest medium Can modify/block network requests declaratively.
- https://web.whatsapp.com/* high Full script+cookie access to WhatsApp Web; session exfil risk.
- https://app.coderlicences.com/* medium Unknown third-party licensing endpoint; data flows outside WhatsApp scope.
Pillar Scores
Permissions6.50
Reputation8.00
Network5.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 11:16
Listing SHA
9112bf25e91f…
Force block
— not fired
Score recovered
no
Elapsed
—