WAPlus CRM - Best AI-Powered Messaging CRM
jmjcgjmipjiklbnfbdclkdikplgajhgc
Risk Score
6.18
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Critical CVE-2021-23358 (arbitrary code execution) in bundled underscore@1.8.3 used in inject-script.js on WhatsApp Web.
- Privacy policy is Google's own policy (not scoped to this extension); admits data collection and third-party sharing.
- Cookies permission on web.whatsapp.com allows full WhatsApp session token exfiltration.
- Free-webmail developer email (gmail) with no developer name and no verified business domain.
- Uninstall URL hijack configured; bit.ly affiliate/cloaking shortlink present in external hosts.
Evidence
- critical_cve crx underscore@1.8.3 in inject-script.js has CVE-2021-23358 (arbitrary code execution); fixed in 1.12.1.
- generic_privacy_policy store Privacy URL is Google's account policy, not scoped to WAPlus; data_collection=true, third_party_sharing=true.
- cookies_on_whatsapp manifest cookies permission + host *://web.whatsapp.com/* enables WhatsApp session cookie read/write.
- free_webmail_no_devname store Developer email veysielle9298@gmail.com; developer_name is empty string; no business domain.
- uninstall_url_hijack crx uninstall_url_hijack=true; post-uninstall redirect to unspecified third party.
- affiliate_hit crx bit.ly in js_external_hosts flagged as affiliate/cloaking redirector.
- no_csp manifest content_security_policy is null on MV3; no CSP declared, amplifying CVE risk.
- verified_publisher_capped store verified_publisher=true but cve_findings nonempty and free-webmail dev; discount capped at -1.0 per 0c.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- tabs medium Can read tab URLs and metadata across all open tabs.
- activeTab low Scoped access to currently active tab only on user gesture.
- storage low Local/sync key-value storage; low risk in isolation.
- cookies high Can read/write cookies for host_permissions scope (WhatsApp session cookies).
- scripting medium Programmatic script injection into matched origins.
- contextMenus low Adds right-click menu items; minimal risk.
- alarms low Schedules background tasks; low risk.
- identity low OAuth token access; risk depends on scopes requested at runtime.
- *://web.whatsapp.com/* high Full access to WhatsApp Web including messages and session cookies.
- *://*.waplus.io/* medium Full access to developer-controlled backend domain.
Pillar Scores
Permissions6.50
Reputation7.00
Network4.00
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure7.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 04:45
Listing SHA
f76f145c10e2…
Force block
— not fired
Score recovered
no
Elapsed
—