Privacy Extension for WhatsApp web
jpmdniboiipfcjdibpahdbibookdhmji
Risk Score
3.22
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Brand impersonation: extension names WhatsApp but confirmed_owner==false and dev uses free Gmail account.
- identity.email permission is unnecessary for a privacy/hide-status tool — collects Google account email.
- Privacy policy URL is the Chrome Web Store listing page itself, not a real policy; scope_extension=true but third_party_sharing=true with no retention disclosure.
- install_url_hijack to premiumsender.com on install — monetization/tracking site linked at install time.
- No CSP declared (MV3 mitigates somewhat) and external JS hosts include premiumsender.com.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true for 'whatsapp'; developer is gmail user, not Meta/WhatsApp Inc.
- install_url_hijack manifest onInstalled opens https://premiumsender.com/privacy-extension-for-whatsapp-web/ — 3rd-party monetization domain.
- identity_email_permission manifest identity + identity.email declared; no stated need for Google account email in a WhatsApp privacy tool.
- privacy_policy_inadequate store Policy URL resolves to own CWS listing (510KB store page). third_party_sharing=true, retention=false.
- free_webmail_developer store Developer email rahul.1990tech@gmail.com — numbered-alias Gmail, no verified business domain.
- external_js_hosts crx js_external_hosts includes premiumsender.com and react.dev; premiumsender.com is install-hijack target.
- verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; discounts reputation but capped due to brand impersonation.
- no_csp manifest content_security_policy=null; MV3 enforces strict default but no explicit CSP tightening declared.
Permissions Breakdown
- tabs medium Can read tab URLs and metadata; moderate risk scoped to WhatsApp use.
- storage low Local data persistence only; no cross-site exfil concern.
- identity medium OAuth token access; combined with identity.email raises account-linkage risk.
- identity.email medium Reads user's Google account email; unnecessary for a WhatsApp privacy tool.
- https://web.whatsapp.com/* medium Host permission limited to WhatsApp web only; scoped but sensitive messaging context.
Pillar Scores
Permissions3.30
Reputation6.50
Network2.00
Webstore5.50
Maintenance0.00
Privacy2.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-15 14:22
Listing SHA
c58e84c7347e…
Force block
— not fired
Score recovered
no
Elapsed
23.2s