Easy Group Contact Extractor for WhatsApp©
ndhmbgnnienbmkefelhnaodahpjgpnnk
Risk Score
4.29
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy URL timed out on fetch — effectively no accessible privacy policy; +10.0 privacy pillar.
- WhatsApp brand impersonation by unaffiliated free-webmail developer (yupdash4@gmail.com); no developer name.
- Content script on web.whatsapp.com reads contact/chat DOM — high-sensitivity personal data surface with no disclosed data handling.
- External JS hosts include momentjs.com and techcrunch.com — unexpected for a contact-extractor; suggests remote resource loading risk.
- Free-webmail developer, no developer name, verified_publisher flag present but dev domain is gmail.com — verification provides little assurance.
Evidence
- privacy_policy_fetch_failed api privacy_policy_classification.fetched==false; ConnectTimeout on https://wasendbulk.com/privacy-policy/ → +10.0 privacy.
- brand_impersonation store brand_mention.is_impersonation==true for 'whatsapp'; developer not confirmed owner; dev domain gmail.com.
- free_webmail_no_dev_name store developer_email=yupdash4@gmail.com; developer_name empty; no business website → reputation floor 7.5.
- content_script_sensitive_origin manifest Content script injected into https://web.whatsapp.com/* — can access contacts, chats, group member data in DOM.
- unexpected_external_js_hosts crx js_external_hosts includes momentjs.com and techcrunch.com — techcrunch.com is irrelevant to a WhatsApp extractor.
- no_csp manifest content_security_policy==null; MV3 strict default applies but external host list raises injection concern.
- verified_publisher_free_webmail store verified_publisher==true but dev email is gmail.com; 0c cap does not save reputation given free-webmail floor rule.
- low_install_count store Only 60 installs; minimal blast radius today but permission surface targets sensitive WhatsApp data.
Permissions Breakdown
- storage low Local key-value storage only; no cross-site data access.
- tabs medium Can read tab URLs and titles; moderate surveillance surface.
- content_scripts_matches: https://web.whatsapp.com/* medium Injects JS into WhatsApp Web; can read contacts/chats in DOM.
Pillar Scores
Permissions2.30
Reputation7.50
Network2.50
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 04:58
Listing SHA
31e7b852145a…
Force block
— not fired
Score recovered
no
Elapsed
—