Privacy Extension For WhatsApp Web
jbojhlhhggfmmkpefknmbdhlaghehini
Risk Score
3.45
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Brand impersonation: extension uses 'WhatsApp' brand name and is not owned/verified by Meta.
- Privacy policy URL points to Chrome Web Store listing page, not a real policy; third_party_sharing admitted without scope.
- Rating of 2.7 across a large install base (1M) suggests quality or trust concerns from real users.
- No developer name listed in store; identity accountability is weak.
- Stale: 15 months since last update on an extension with 1M installs and no CSP raises option-value risk.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true for 'whatsapp'; confirmed_owner=false; developer is lukaslen.com, not Meta.
- privacy_policy_url_invalid store Privacy policy URL is the extension's own CWS listing page, not a standalone policy document.
- privacy_third_party_sharing api privacy_policy_classification: scope_extension=true, data_collection=false, third_party_sharing=true, retention=false.
- low_rating store Rating 2.7 on 1M-install extension; no review red flags in structured scan but low score is notable.
- no_developer_name store developer_name is empty string; only contact@lukaslen.com available for attribution.
- stale_extension store months_since_update=15; in 6-12 month band for maintenance scoring.
- no_csp manifest content_security_policy=null; MV3 has strict default so no extra Network penalty, but dom-sink risk unmitigated.
- verified_publisher store verified_publisher=true; applies reputation discount but impersonation overrides full benefit per v3.2 rule (9).
Permissions Breakdown
- storage low Stores extension preferences locally; minimal risk.
- host_permission: https://web.whatsapp.com/* medium Scoped to WhatsApp Web only; matches stated function as a WhatsApp privacy tool.
- content_scripts: https://web.whatsapp.com/* medium Injects scripts into WhatsApp Web; consistent with stated purpose but grants DOM access.
Pillar Scores
Permissions1.30
Reputation5.50
Network0.00
Webstore3.50
Maintenance6.00
Privacy2.00
Code Quality0.00
CVE Exposure0.00
Scoring History
| sssiednd56c5bc5dp727562726963xsx | 2.79 | Low | review | 2026-09-07 |
| %F6"onmouseover=dMam(96645)// | 2.83 | Low | review | 2026-08-05 |
| dfb{{98991*97996}}xca | 1.96 | Low | review | 2026-08-05 |
| bfg8966<s1﹥s2ʺs3ʹhjl8966 | 2.83 | Low | review | 2026-08-05 |
| v3.6&n930880=v937066 | 2.88 | Low | review | 2026-08-05 |
| v3.6"><script>nTUJ(9319)</script> | 2.76 | Low | review | 2026-08-04 |
| v3.6"onmouseover=nTUJ(90812)" | 2.16 | Low | review | 2026-08-04 |
| bfg10289<s1﹥s2ʺs3ʹhjl10289 | 2.65 | Low | review | 2026-08-04 |
| v3.6&n950672=v953334 | 2.70 | Low | review | 2026-08-04 |
| v3.6"sTYLe='zzz:Expre/**/SSion(NdJi(9059))'bad=" | 3.05 | Low | review | 2026-07-29 |
| v3.6"onmouseover=NdJi(96282)" | 2.81 | Low | review | 2026-07-29 |
| 1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%> | 3.06 | Low | review | 2026-07-29 |
| "dfbzzzzzzzzbbbccccdddeeexca".replace("z","o") | 3.00 | Low | review | 2026-07-29 |
| <th:t="${dfb}#foreach | 2.50 | Low | review | 2026-07-29 |
| v3.69406329< | 3.34 | Low | review | 2026-07-29 |
| v3.6'"()&%<zzz><ScRiPt >NdJi(9467)</ScRiPt> | 2.72 | Low | review | 2026-07-29 |
| v3.6&n913574=v945062 | 2.67 | Low | review | 2026-07-29 |
| v3.6 | 3.45 | Low | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:44
Listing SHA
7413ad753287…
Force block
— not fired
Score recovered
no
Elapsed
20.2s