Fronty Leads
lackhjbdjbnbbhbpoaloegokakncjfeg
Risk Score
5.24
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic policy — does not scope to this extension, admits data collection and 3rd-party sharing (D rule: +10.0).
- WhatsApp brand impersonation: developer domain extensao.store is not affiliated with Meta/WhatsApp.
- Uninstall and install URL hijack both flagged; install redirects to web.whatsapp.com (obfuscates behavior).
- 12 distinct external JS hosts under wascript.com.br / watools.com.br with no CSP — large remote attack surface.
- function_constructor (new Function) and innerHTML DOM-XSS sink found in scanned JS files.
Evidence
- privacy_policy_generic_google store Privacy URL is myaccount.google.com/privacypolicy — Google's own policy, scope_extension=false, data_collection+third_party_sharing=true → +10.0 privacy.
- brand_impersonation_whatsapp store brand_mention.is_impersonation=true for 'whatsapp'; developer domain extensao.store not verified → +2.0 reputation.
- uninstall_and_install_url_hijack manifest uninstall_url_hijack=true, install_url_hijack=true (target: https://web.whatsapp.com) → +3.0+2.0 webstore.
- external_js_hosts crx 12 distinct external JS hosts (wascript.com.br, watools.com.br etc.) with no CSP → high network reach.
- code_function_constructor crx new Function() constructor found → +2.5 code quality (function_constructor signal).
- code_innerhtml_no_csp crx innerHTML user-controlled sink with csp_present=false → +2.0 code quality (FIX B).
- no_csp_mv3 manifest content_security_policy=null; MV3 so no +2.0 network penalty, but amplifies code findings.
- developer_identity_weak store developer_name='wsll', no verified publisher, no featured badge; email on .store TLD → elevated reputation risk.
Permissions Breakdown
- unlimitedStorage low Local storage only; no cross-origin data exfil on its own.
- storage low Standard extension storage; low standalone risk.
- alarms low Scheduling only; no data access.
- tabs medium Can read tab URLs and titles; elevated when paired with WhatsApp host.
- https://web.whatsapp.com/* medium Scoped to WhatsApp Web; content scripts can read messages and DOM.
Pillar Scores
Permissions2.30
Reputation7.00
Network3.50
Webstore8.00
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 04:36
Listing SHA
662dc95d0100…
Force block
— not fired
Score recovered
no
Elapsed
—