Botzaper Premium
klhdlmakggjklhafembcfpopdoideecl
Risk Score
4.52
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's own policy — not scoped to this extension, admits data collection and 3rd-party sharing.
- WhatsApp impersonation brand mention by unverified gmail developer; content scripts can exfiltrate messages.
- Install URL hijack on onInstalled opens 3rd-party URL, a monetization/tracking pattern.
- Audio transcription endpoint (audio-transcriber.wascript.com.br) may receive sensitive voice data from WhatsApp.
- No CSP with function_constructor usage across 896 JS files; dynamic code execution risk.
Evidence
- privacy_policy_google_generic store Policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true — worst-case generic policy.
- brand_impersonation store brand_mention.is_impersonation=true for WhatsApp; developer is unverified gmail user, not Meta.
- install_url_hijack manifest install_url_hijack=true; onInstalled opens 3rd-party URL — common monetization/tracking shell pattern.
- function_constructor_no_csp crx 3 instances of new Function() constructor across JS bundle; csp_present=false amplifies dynamic code execution risk.
- whatsapp_host_permission manifest Full scripting access to web.whatsapp.com; combined with audio/message API endpoints, broad message data exposure.
- geo_diversity crx JS hosts span 4 countries (BR, CA, LT, US); LT presence is unusual for a BR WhatsApp productivity tool.
- gmail_dev_no_business store Developer email startupagencia.adm@gmail.com is free-webmail; no verified publisher; developer_domain_info=null.
- external_backend_lotsofwms_in manifest host_permission includes backend.lotsofwms.in — third-party .in domain unrelated to developer identity.
Permissions Breakdown
- unlimitedStorage low Allows large local data storage; low direct harm alone.
- storage low Standard local key-value store; low risk.
- alarms low Scheduling only; low risk.
- tabs medium Can read tab URLs and metadata across all open tabs.
- scripting medium Can inject scripts into matching pages (WhatsApp); significant capability.
- https://web.whatsapp.com/* high Full DOM/script access to WhatsApp Web; can read messages and contacts.
- https://backend.lotsofwms.in/* medium External backend in .in TLD; unclear ownership, potential data exfil target.
- https://backend-utils.wascript.com.br/* medium Developer-controlled backend; data routing unknown.
- https://audio-transcriber.wascript.com.br/* medium Audio data may be sent to this endpoint; sensitive content risk.
- https://api-whatsapp.wascript.com.br/* medium WhatsApp-specific API endpoint; message data could be forwarded.
- https://multi-atendimento.wascript.com.br/* medium Multi-attendance backend; conversation data exposure risk.
- https://botzaper.digital/* medium Primary product domain; data aggregation point.
Pillar Scores
Permissions4.30
Reputation7.50
Network4.50
Webstore5.50
Maintenance3.50
Privacy10.00
Code Quality2.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 16:55
Listing SHA
3358f618493e…
Force block
— not fired
Score recovered
no
Elapsed
—