Wischat
mehipcdhalmoecjhhfcgmiodeokllnno
Risk Score
3.39
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- jQuery 3.4.1 bundled with 2 medium CVEs (XSS); no CSP amplifies risk per v2 CVE amplifier.
- Privacy policy not scoped to this extension and lacks retention/third-party details; +9.0 privacy score.
- bit.ly host permission flagged as affiliate/cloaking vector by threat_intel.
- dom_sink_innerhtml_userctrl in strophe.umd.min.js with no CSP raises DOM-XSS surface.
- disisot.com host permission unexplained by stated function.
Evidence
- jquery_cve_no_csp crx jquery@3.4.1 has CVE-2020-11022 and CVE-2020-11023 (medium XSS); no CSP present — v2 amplifier ×1.5 applies.
- privacy_policy_not_scoped api Privacy policy fetched but scope_extension=false, data_collection=false → +9.0 privacy pillar.
- affiliate_hit_bitly crx bit.ly in host_permissions; threat_intel flags as affiliate/cloaking redirector.
- dom_xss_sink_no_csp crx innerHTML sink in strophe.umd.min.js; csp_present=false triggers +2.0 code quality rule FIX B.
- unexplained_host_disisot manifest disisot.com host permission not mentioned in description or store page.
- verified_publisher store verified_publisher=true; nouxsoft.com resolves, no throwaway flag — provides partial reputation credit.
- no_developer_name store developer_name is empty string; no 'Offered by' display name visible.
- low_installs store Only 70 installs; blast radius low but tail_attack_surface not triggered per anomaly check.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2020-11022 | jquery@3.4.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.4.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- storage low Local data persistence; low sensitivity.
- scripting medium Allows programmatic script injection into pages.
- *://*.whatsapp.com/* medium Access to WhatsApp web; matches stated function (chat integration).
- *://*.wis.chat/* low Dev-controlled domain; expected for product backend.
- *://*.disisot.com/* medium Unknown third-party domain; unexplained host access.
- *://*.wa.link/* low WhatsApp short-link domain; ancillary to chat function.
- *://*.wa.me/* low WhatsApp click-to-chat domain; ancillary to chat function.
- *://bit.ly/* medium Generic URL shortener; affiliate/cloaking risk flagged by threat_intel.
- *://localhost/* low Local dev endpoint; low real-world impact.
- *://127.0.0.1/* low Loopback only; dev/debug pattern.
Pillar Scores
Permissions2.30
Reputation4.50
Network3.50
Webstore2.00
Maintenance0.00
Privacy9.00
Code Quality2.50
CVE Exposure4.50
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 04:54
Listing SHA
46f01a3291e9…
Force block
— not fired
Score recovered
no
Elapsed
—