WA Self Sender & Easy Sender - Personalized WhatsApp Messages & Group Tools
khfmfdepnleebhonomgihppncahojfig
Risk Score
6.77
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Critical CVE (CVE-2021-23358) in bundled underscore@1.8.3 enables arbitrary code execution; no CSP amplifies risk.
- Content script declared for <all_urls> — far exceeds stated WhatsApp-only purpose; scope mismatch +1.0.
- Privacy policy is Google's generic account policy (scope_extension=false, admits data collection + 3rd-party sharing) — +10.0 privacy pillar.
- Brand impersonation of WhatsApp by unverified free-webmail developer (shuttershanti708@gmail.com) with no developer name.
- Uninstall URL hijack confirmed; 12 external JS hosts including cdn2.waplus.io and third-party domains beyond dev control.
Evidence
- critical_cve_underscore crx underscore@1.8.3 has CVE-2021-23358 (critical, arbitrary code execution); fixed in 1.12.1. No CSP present.
- content_scripts_all_urls manifest content_scripts_matches includes <all_urls> — extension injects into every site despite WhatsApp-only stated purpose.
- brand_impersonation_whatsapp store brand_mention.is_impersonation=true for WhatsApp; developer is unverified free-webmail gmail account, no developer name.
- generic_google_privacy_policy store Privacy policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- uninstall_url_hijack crx uninstall_url_hijack=true — extension overrides uninstall redirect to third-party URL.
- function_constructor_new_Function crx new Function() constructor found in js/background.js and pay/js/element-ui_2.15.14.js — dynamic code execution risk.
- 12_external_js_hosts crx 12 distinct external hosts including cdn2.waplus.io, waselfsender.com, wawebsender.com, sheetjs.com beyond dev-owned domains.
- no_csp_mv3 manifest content_security_policy is null; MV3 default applies but no explicit CSP hardening for CVE-bearing DOM-manipulation libs.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- activeTab low Access to current tab on user action only; limited scope.
- storage low Local data persistence; low standalone risk.
- unlimitedStorage low Removes storage quota; could store large harvested data sets.
- scripting medium Programmatic script injection; high-impact when paired with broad host access.
- *://*.whatsapp.com/* (host) high Full access to WhatsApp Web: can read/send messages, harvest contacts.
- <all_urls> (content_scripts) high Content script declared for ALL URLs — far broader than stated WhatsApp purpose.
Pillar Scores
Permissions6.50
Reputation8.50
Network5.50
Webstore8.50
Maintenance0.00
Privacy10.00
Code Quality6.50
CVE Exposure7.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:49
Listing SHA
9a8d4ab1e8fb…
Force block
— not fired
Score recovered
no
Elapsed
35.7s