WhatsBlast — WhatsApp Bulk Sender + CRM | Leadgrabr
jnghfafinjlkhgfbphnldgchmbahkjma
Risk Score
4.06
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- WhatsApp brand impersonation: dev domain is leadgrabr.com, not Meta/WhatsApp — unverified third party.
- Privacy policy is 58 chars, not extension-scoped, and admits no data collection — likely placeholder.
- Content script on web.whatsapp.com reads live chat DOM; bulk-sender function has high message-abuse potential.
- External JS host cool-cake-8a5d.akshay-kini.workers.dev (Cloudflare Worker) creates supply-chain risk.
- Two DOM-XSS innerHTML sinks in CRM and popup code with no CSP to mitigate.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true for WhatsApp; dev domain leadgrabr.com not confirmed owner.
- privacy_policy_stub api Policy fetched but only 58 chars; scope_extension=false, data_collection=false — likely placeholder.
- external_worker_host crx js_external_hosts includes cool-cake-8a5d.akshay-kini.workers.dev — personal Cloudflare Worker.
- dom_xss_sink crx Two innerHTML sinks in crm-panel.js and popup.js; no CSP present (MV3 default only).
- no_developer_name store developer_name is empty string; only email Akshay.kini@leadgrabr.com available.
- whatsapp_content_script manifest Content script runs on https://web.whatsapp.com/* — full chat DOM access including messages and contacts.
- no_verified_publisher store verified_publisher=false, is_featured_by_google=false; 7 installs only.
- third_party_silence api privacy_policy_classification.third_party_silence=true; policy does not mention third-party sharing.
Permissions Breakdown
- storage low Stores local CRM/contact data; scoped to extension.
- tabs medium Can read tab URLs; needed to detect WhatsApp Web tab.
- alarms low Schedules reminders; low abuse potential alone.
- notifications low Sends desktop notifications; no data exfil risk.
- host: https://web.whatsapp.com/* medium Content script on WhatsApp Web — can read chat DOM, contacts, messages.
Pillar Scores
Permissions2.30
Reputation7.00
Network2.50
Webstore3.50
Maintenance0.00
Privacy9.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 04:41
Listing SHA
17987fbc8df9…
Force block
— not fired
Score recovered
no
Elapsed
—