Brasilbot
lbcfbjpjhighachiefcllehigodnlokm
Risk Score
4.68
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- cookies permission scoped to WhatsApp Web enables full session token capture from a sensitive messaging platform
- Privacy policy is Google's own generic policy — does not describe this extension's data collection at all (v3.5 D: +10.0)
- Free-webmail developer (gmail), no developer name, no verified publisher status raises accountability concerns
- js_external_hosts load from notiflix.github.io and reactjs.org — no CSP; external script integrity not enforced
- install_perm_anomaly: 2 installs with high-tier permissions is tail-attack-surface signal
Evidence
- cookies+WhatsApp host permission manifest cookies permission + host https://web.whatsapp.com/* allows full session cookie read/write on WhatsApp Web.
- generic Google privacy policy store Policy URL is myaccount.google.com — scope_extension=false, data_collection=true, third_party_sharing=true. Scores +10.0 under v3.5 D.
- free-webmail developer, no name store developer_email=fgpmonteiro@gmail.com, developer_name empty, no verified publisher badge.
- external JS hosts, no CSP crx js_external_hosts=[notiflix.github.io, reactjs.org], csp_present=false. Remote CDN without integrity enforcement.
- install_perm_anomaly api installs=2, small_install_high_perm=true. High permissions for near-zero user base is tail-attack-surface risk.
- no code findings / obfuscation crx js_files_scanned=0, obfuscation_score=0.0, code_findings_raw empty — CRX surface unverifiable.
- no bad host / CVE hits api threat_intel.bad_host_hits=[], cve_findings_raw=[] — no known-malicious infrastructure detected.
- wayback ownership check api wayback_ownership.ownership_changed=false, first_snapshot=null (fetch_error:ReadTimeout). No transfer evidence.
Permissions Breakdown
- storage low Standard key-value storage, low risk.
- unlimitedStorage low Allows large local storage; no direct exfil path alone.
- tabs medium Can read tab URLs and metadata across all open tabs.
- cookies high Can read/write cookies; scoped to whatsapp.com and app.coderlicences.com host permissions.
- notifications low Can display desktop notifications; limited abuse surface.
- declarativeNetRequest medium Can block/redirect network requests declaratively.
- https://web.whatsapp.com/* high Full access to WhatsApp Web session including messages and auth cookies.
- https://app.coderlicences.com/* medium Access to developer's own licensing endpoint; unknown data practices.
Pillar Scores
Permissions5.30
Reputation7.50
Network2.00
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 11:18
Listing SHA
644b54d2d6b6…
Force block
— not fired
Score recovered
no
Elapsed
—