SellerHub360
jhmokkkndhlngbphddmpipnjpnoklpdb
Risk Score
5.24
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's own policy — not scoped to this extension; admits data collection and 3rd-party sharing (score +10).
- WhatsApp brand impersonation by unverified developer 'Intzp' on unrelated domain extensao.store.
- Uninstall and install URL hijacks detected; install redirects to web.whatsapp.com (suspicious onboarding flow).
- 10+ distinct external JS hosts under wascript.com.br/watools.com.br contacted — large undisclosed backend surface.
- function_constructor and innerHTML DOM-XSS sink found in 334 JS files with no CSP; arbitrary code execution risk.
Evidence
- privacy_policy_generic_google store Privacy URL is myaccount.google.com/privacypolicy — Google's own policy, not scoped to SellerHub360; data_collection+3rd_party_sharing=true.
- brand_impersonation_whatsapp store brand_mention.is_impersonation=true; developer domain extensao.store confirmed_owner=false.
- uninstall_and_install_url_hijack crx uninstall_url_hijack=true and install_url_hijack=true; install target https://web.whatsapp.com.
- large_external_host_surface crx 11 js_external_hosts across wascript.com.br and watools.com.br sub-domains; >3 distinct registrable domains.
- function_constructor_code_finding crx new Function() constructor found in content JS — dynamic code execution risk, no CSP to mitigate.
- dom_xss_sink_no_csp crx innerHTML from variable found; csp_present=false amplifies DOM-XSS risk (FIX B applies).
- very_low_installs_developer_unverified store Only 7 installs; not verified publisher, not featured; developer name 'Intzp' provides minimal accountability.
- mv3_no_csp_declared manifest MV3 extension has no content_security_policy set; default MV3 CSP applies but no explicit hardening.
Permissions Breakdown
- unlimitedStorage low Allows large local data storage; low standalone risk.
- storage low Standard key-value store; low risk.
- alarms low Scheduled background tasks; low standalone risk.
- tabs medium Can read tab URLs and titles; moderate risk combined with content scripts.
- https://web.whatsapp.com/* medium Host permission scoped to WhatsApp Web only; enables full page script access on that origin.
Pillar Scores
Permissions2.30
Reputation7.00
Network3.50
Webstore8.00
Maintenance0.00
Privacy10.00
Code Quality4.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 10:15
Listing SHA
ac094b45f8e9…
Force block
— not fired
Score recovered
no
Elapsed
—