EaseZap
jlplnjdjnhkdigmpooonjmjppdkahljh
Risk Score
3.71
Risk Level:
Low
Recommendation:
🚫 BLOCK
Top Risks
- Uninstall AND install URL hijack: extension intercepts browser lifecycle events to redirect users to third-party URLs.
- Privacy policy is Google's own policy (generic, unscoped) — admits data collection and third-party sharing with no extension-specific scope.
- WhatsApp brand impersonation: developer domain (extensao.store) is not affiliated with Meta/WhatsApp.
- 10 external JS hosts under wascript.com.br / watools.com.br contacted at runtime — large unverified backend surface.
- new Function() constructor in content script running on WhatsApp Web enables dynamic code execution against chat data.
Evidence
- install/uninstall URL hijack crx uninstall_url_hijack=true, install_url_hijack=true with target https://web.whatsapp.com — lifecycle events abused.
- generic Google privacy policy store Policy URL is myaccount.google.com/privacypolicy — not scoped to EaseZap; data_collection+third_party_sharing=true.
- WhatsApp brand impersonation store brand_mention.is_impersonation=true; dev domain extensao.store not affiliated with Meta.
- 10 external JS hosts crx Contacts api-whatsapp.wascript.com.br, app.wascript.com.br, backend-plugin.wascript.com.br + 7 more at runtime.
- function_constructor in content script crx new Function() found in content script on WhatsApp Web — allows dynamic code execution against chat session.
- innerHTML DOM-XSS sink crx Unguarded innerHTML assignment in content script without CSP; DOM-XSS risk in WhatsApp context.
- no CSP + MV3 manifest csp_present=false; MV3 has strict default but no explicit CSP declared alongside 334 JS files.
- very low install count store Only 22 installs; unverified publisher, no ratings count — minimal community validation.
Permissions Breakdown
- unlimitedStorage low Allows unbounded local storage; low direct harm but enables large local data accumulation.
- storage low Standard key-value storage; low risk in isolation.
- alarms low Scheduled tasks only; low risk.
- tabs medium Can read tab URLs and titles; medium risk when combined with WhatsApp host access.
- https://web.whatsapp.com/* medium Scoped host access to WhatsApp Web; can read/modify all WhatsApp chat content.
Pillar Scores
Permissions2.30
Reputation7.00
Network4.00
Webstore8.00
Maintenance0.00
Privacy10.00
Code Quality4.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 04:31
Listing SHA
f14d4ea3fc95…
Force block
— not fired
Score recovered
no
Elapsed
—