Crm Grátis
ljdglkbjbimcfogoknmggdcjlnddamil
Risk Score
5.33
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Cookie access on WhatsApp Web enables session hijacking and message interception.
- Privacy policy is Google's generic policy — does not scope to this extension or disclose collection.
- Free-webmail developer (gmail), no verified publisher, 3 installs — high tail-attack-surface risk.
- new Function() constructor and multiple innerHTML DOM-XSS sinks in content/background scripts.
- No CSP declared (MV3 mitigates partially) but DOM sinks + no CSP amplifies XSS risk.
Evidence
- cookies + WhatsApp host access manifest cookies permission paired with https://web.whatsapp.com/* enables reading WhatsApp session cookies.
- generic Google privacy policy store Privacy URL points to myaccount.google.com/privacypolicy — not scoped to this extension; data_collection=true, third_party_sharing=true.
- free-webmail developer, no verified publisher store Developer email coderlicences@gmail.com; verified_publisher=false; is_featured=false; 3 installs.
- new Function() constructor in app.js crx function_constructor signal found; dynamic code execution risk in content context.
- innerHTML DOM-XSS sinks (3 files) crx dom_sink_innerhtml_userctrl in app.js, background.js, contentScript.js; no CSP to mitigate.
- install_perm_anomaly api small_install_high_perm=true; 3 installs with cookies + tabs + declarativeNetRequest + WhatsApp host.
- external JS hosts manifest js_external_hosts: notiflix.github.io, reactjs.org — remote CDN references in extension context.
- wayback ownership check api Wayback fetch error; no ownership-change confirmed but dev domain not verifiable via CT logs (free webmail).
Permissions Breakdown
- storage low Standard local data storage; low risk.
- unlimitedStorage low Allows large local storage; minor risk.
- tabs medium Can read tab URLs and metadata across browser.
- cookies high Can read/write cookies; combined with host access to WhatsApp this is elevated risk.
- notifications low Can show notifications; nuisance risk only.
- declarativeNetRequest medium Can block/redirect network requests; moderate risk.
- https://web.whatsapp.com/* high Full access to WhatsApp Web including messages; high sensitivity.
- https://app.coderlicences.com/* medium Dev-controlled backend; data exfil surface.
Pillar Scores
Permissions5.00
Reputation7.50
Network2.00
Webstore5.50
Maintenance1.50
Privacy10.00
Code Quality5.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-15 13:05
Listing SHA
c5ba899a0e73…
Force block
— not fired
Score recovered
no
Elapsed
—