Disparô/Wa - Disparo no WhatsApp, CRM, Automações, Ferramentas para Venda
jhokpeoaapahcoaigkfnienliabeaang
Risk Score
6.33
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Operator cluster of 18 extensions sharing identical dev email and host fingerprint — mass deployment pattern.
- Uninstall and install URL hijacks both present; installs opens web.whatsapp.com redirect.
- Privacy policy is Google's own policy — not scoped to this extension; admits data collection and 3rd-party sharing.
- WhatsApp brand impersonation: dev domain extensao.store is not confirmed Meta/WhatsApp owner.
- 10+ distinct external backend hosts (wascript.com.br, watools.com.br) contacted; function_constructor found in JS.
Evidence
- operator_cluster_large api sibling_count=17 extensions sharing same dev email, install URL, and CSP host set — coordinated deployment.
- uninstall_url_hijack crx uninstall_url_hijack=true; install_url_hijack=true targeting https://web.whatsapp.com.
- privacy_policy_generic store Policy URL is myaccount.google.com/privacypolicy — Google's own policy, not scoped to this extension.
- brand_impersonation store brand_mention.is_impersonation=true for 'whatsapp'; developer domain extensao.store not confirmed owner.
- external_backends crx 10 external hosts under wascript.com.br and watools.com.br contacted; no CSP to restrict them.
- function_constructor crx new Function() found in JS — dynamic code execution risk.
- dom_sink_innerhtml crx innerHTML assigned from variable in content script running on WhatsApp Web — DOM-XSS sink with no CSP.
- reputation_anonymous_dev store Developer name 'ewdht' is opaque; not verified publisher; no featured badge; dev email on extensao.store.
Permissions Breakdown
- unlimitedStorage low Local storage quota removal; low direct risk but enables large local data caching.
- storage low Standard local extension storage; low risk.
- alarms low Scheduling alarms; low risk on its own.
- tabs medium Access to tab URLs/titles; medium risk, can enumerate browsing context.
- https://web.whatsapp.com/* medium Content script + host access on WhatsApp Web; can read all messages and DOM.
Pillar Scores
Permissions2.30
Reputation7.50
Network3.50
Webstore10.00
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure0.00
Operator Siblings (24)
Other extensions sharing this developer's compound fingerprint:
- cellckcnenolgakggljkichbmgmbibgb
- aocojboaoklgedadlpaallelnanhcpgm
- bgnkgembgfkfjipflkniiibgcedloekn
- bjhbgbfapjofmjcoonncefneakppmkmo
- bpgbjcgkegcecddlnlckjcoddhpmekdh
- cplaeebopfpnoebkaimlibpdickcjofa
- afdhcpnimkgccfjcelgkiipidhebddjh
- abkolnpebgghiglkkdjcgjgbpnddmfmp
- gjlfpggiddcminhebiejofeglfjmleli
- gkkkdobapmhkaihggejlcdbjemfkhdgk
- gollbfedpcfodjgfjddbkfnkkfdedknn
- hcbmcbkjjklkjidikpggmmfpfklcpnmb
- hkdbocoaofpdmbbgpimdkhcafenpkikn
- iibldfhmeiipohbjlkhfgnjhcmkknffi
- ikliliinakofoiojghnipegfphmoljla
- jeicljefnlpdoblklfdephbpihhjgphf
- jkblcpmoooocmdcfjojdecccejlkicap
- jcjodbceolndbhnbljiedcanmglmhmop
- lfenojckeamfnllggndghkmfhkheiimc
- ngnffiapbonmlgijfnlcgbdomhgcmmna
- lhadifphljjldcidjbhdpfcoemhddeec
- hdagfineacponepnaljjkkgjoddgpjld
- dkgcodmnjmlmgmdlbekkcjjjidkflnal
- hpfmfjmhhkfpcedjikogphkfacokfagh
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 15:11
Listing SHA
a7048f6c7882…
Force block
— not fired
Score recovered
no
Elapsed
—