WTF
kcdlihaidnmkenhlnofkjfoachidbnif
Risk Score
3.72
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension at all (D-clause: +10.0 privacy).
- Extension not updated for 20 months; stale codebase increases supply-chain risk.
- Two innerHTML DOM-XSS sinks in popup.js and options.js with no CSP to mitigate.
- No content_security_policy declared; MV3 default applies but innerHTML sinks unmitigated.
- Low install count (211) limits blast radius, but stale + unscoped policy is concerning.
Evidence
- privacy_policy_generic store Policy URL is Google's own account privacy page — scope_extension=false, data_collection=true, third_party_sharing=true. Triggers +10.0 privacy (D-clause).
- maintenance_stale store Last updated December 8, 2024 — 20 months ago. Maintenance score +6.0 (12-24mo band).
- dom_xss_sinks crx innerHTML assigned from variable in options.js and popup.js; no CSP present to block exploitation.
- no_csp manifest content_security_policy is null; csp_present=false. DOM sinks unmitigated (FIX B: +2.0 code quality).
- narrow_permissions manifest Only activeTab + storage; content_scripts scoped solely to web.whatsapp.com. Very low permission surface.
- no_bad_hosts api threat_intel bad_host_hits, monetization_hits, affiliate_hits all empty. No threat-intel concerns.
- unverified_publisher store verified_publisher=false, not featured. Developer domain resolves, not throwaway, no impersonation.
- cve_none crx cve_findings_raw empty; js_libraries_detected empty. CVE pillar = 0.0.
Permissions Breakdown
- activeTab low Only accesses current tab on user action; scoped to web.whatsapp.com.
- storage low Local extension storage; no cross-origin data exposure.
- content_scripts: https://web.whatsapp.com/* low Narrow single-domain scope; matches stated WhatsApp utility function.
Pillar Scores
Permissions0.60
Reputation5.00
Network0.00
Webstore0.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 04:50
Listing SHA
a7302b34adfc…
Force block
— not fired
Score recovered
no
Elapsed
—