Privacy Extension For WhatsApp Web - wabulk.net
mbcghjiodcjankhkllfohcgnckhdbkmi
Risk Score
3.38
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Brand impersonation: uses 'WhatsApp' brand name without confirmed ownership; is_impersonation=true.
- Uninstall URL hijack: redirects to privacy-wa-web.wabulk.net/suggestion on removal — monetization/data-harvest signal.
- Privacy policy URL points to Chrome Web Store listing page, not a real policy; third_party_sharing admitted with no retention disclosed.
- Content script executes on web.whatsapp.com — direct access to WhatsApp Web DOM including message content.
- External host ext.leadsext.com contacted — name suggests lead-generation/ad-tech; not in threat_intel but warrants scrutiny.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true for 'whatsapp'; confirmed_owner=false; dev domain wabulk.net unrelated to Meta.
- uninstall_url_hijack crx uninstall_url_hijack=true; target=https://privacy-wa-web.wabulk.net/suggestion — post-removal redirect.
- privacy_policy_inadequate store Policy URL resolves to CWS listing page (519KB); scope_extension=true but retention=false, third_party_sharing=true.
- external_host_leadsext crx js_external_hosts includes ext.leadsext.com — domain name implies lead-generation/ad-tech endpoint.
- content_script_whatsapp manifest content_scripts_matches=[https://web.whatsapp.com/*]; injects into WhatsApp Web session with message DOM access.
- no_csp crx csp_present=false on MV3; v2 calibration +2.0 Network penalty applied.
- verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; mitigates reputation but does not excuse impersonation.
- no_code_findings crx code_findings_raw=[], obfuscation_score=0.0; no malicious code patterns detected in 10 JS files.
Permissions Breakdown
- storage low Local key-value storage; no direct data exfil risk.
- tabs medium Can read tab URLs/titles; moderate surveillance surface.
- unlimitedStorage low Extends storage quota; low standalone risk.
- commands low Keyboard shortcut binding; minimal risk.
- content_scripts:https://web.whatsapp.com/* medium Injects JS into WhatsApp Web; can read messages and DOM.
Pillar Scores
Permissions2.30
Reputation4.50
Network3.50
Webstore6.50
Maintenance0.00
Privacy2.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:54
Listing SHA
be93e43d5b13…
Force block
— not fired
Score recovered
no
Elapsed
23.0s