Pipechat for WhatsApp Web
mbfdhkodejajhcnoljjgkdbdmacahcoc
Risk Score
4.56
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Content script injected into WhatsApp Web gives full read access to private messages and contacts.
- Brand impersonation: extension claims WhatsApp affiliation but developer is not a confirmed WhatsApp owner.
- Privacy policy fetched but scope_extension==false and admits data collection + third-party sharing — worst policy tier.
- No developer name listed; low rating (2.9) raises accountability concern.
- No CSP declared (MV3 mitigates but inline risks remain); policy admits third-party data sharing.
Evidence
- brand_impersonation store brand_mention.is_impersonation==true for 'whatsapp'; confirmed_owner==false.
- privacy_policy_admits_collection_and_sharing api fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 rule D).
- content_script_on_whatsapp manifest content_scripts_matches includes https://web.whatsapp.com/* giving DOM+message access.
- no_developer_name store developer_name is empty string; +1.0 reputation penalty.
- low_rating store Rating 2.9 but rating_count not provided; cannot apply >=50 threshold penalty definitively.
- is_featured_by_google store is_featured_by_google==true; applies -2.0 reputation discount.
- no_cve_findings crx cve_findings_raw empty; CVE pillar = 0.0.
- no_code_findings crx code_findings_raw empty, obfuscation_score=0.0; code quality pillar = 0.0.
Permissions Breakdown
- tabs medium Can read tab URLs and titles; moderate data exposure.
- storage low Stores extension data locally; low standalone risk.
- content_scripts@https://web.whatsapp.com/* high Script injection into WhatsApp Web; full access to messages and DOM.
- content_scripts@https://pdwa.pipechat.app/* medium Script injection into developer's own domain; lower third-party risk.
Pillar Scores
Permissions3.50
Reputation7.00
Network2.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:54
Listing SHA
3161970f3a04…
Force block
— not fired
Score recovered
no
Elapsed
18.7s