GD CRM the World’s No.1 WhatsApp CRM for WhatsApp Web
leoaecjkfkmbnapicngpoohkbohmhjki
Risk Score
6.15
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- WhatsApp brand impersonation by unverified developer; no verified publisher badge or developer identity.
- Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection & 3rd-party sharing.
- Uninstall and install URL hijack detected; redirects user to WhatsApp Web on install.
- Content injected into WhatsApp Web with access to 9 host origins including OpenAI, Groq, Anthropic, and wascript.com.br backends.
- No CSP on MV3 extension with function_constructor and innerHTML DOM-XSS sinks in 309 JS files.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true for 'whatsapp'; developer not confirmed owner.
- uninstall_url_hijack manifest uninstall_url_hijack=true; install_url_hijack=true targeting https://web.whatsapp.com.
- generic_privacy_policy store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- no_developer_identity store developer_name, developer_email, and title fields all empty; no verified publisher.
- broad_ai_backends manifest Host perms include api.openai.com, api.groq.com, api.anthropic.com (js_external_hosts); WhatsApp data sent to AI APIs.
- function_constructor_code crx new Function() usage in 309-file JS bundle; no CSP; DOM-XSS innerHTML sink also present.
- no_csp manifest csp_present=false on MV3 extension with code execution sinks.
- multiple_external_hosts crx 12 distinct external JS hosts including license.geniusdevel.in, wascript.com.br subdomains, vercel.app wildcard.
Permissions Breakdown
- unlimitedStorage low Local storage expansion; low direct harm potential.
- storage low Standard key-value storage, low risk.
- alarms low Scheduling; used for automation tasks, low risk.
- tabs medium Can read tab URLs and metadata across sessions.
- *://*.whatsapp.com/* high Full access to WhatsApp Web — reads chats, contacts, messages.
- *://license.geniusdevel.in/response/gdcrm/* medium License server endpoint; external dependency risk.
- *://*.vercel.app/* medium Broad Vercel wildcard — any Vercel-hosted app reachable.
- *://wascript.com.br/* medium Third-party backend; unverified data flows.
- https://painel.wascript.com.br/* medium Admin panel endpoint; potential data exfiltration surface.
- https://generativelanguage.googleapis.com/* medium Google Gemini AI API; sends user data to AI provider.
- https://api.groq.com/* medium Groq AI API; third-party AI provider receives user data.
- https://api.openai.com/* medium OpenAI API; WhatsApp message content may be forwarded.
- https://www.gdcrm.store/* medium Developer storefront; unclear what data is sent.
Pillar Scores
Permissions4.30
Reputation8.50
Network5.00
Webstore8.50
Maintenance0.00
Privacy10.00
Code Quality4.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 08:49
Listing SHA
008c61e6b95d…
Force block
— not fired
Score recovered
no
Elapsed
—