Botzom – Vendas, CRM e Chatbot para WhatsApp
ngnffiapbonmlgijfnlcgbdomhgcmmna
Risk Score
6.27
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Operator cluster of 19 sibling extensions under same developer fingerprint — mass-deployment shell pattern.
- Privacy policy is Google's own policy (myaccount.google.com) — not scoped to this extension; admits data collection and 3rd-party sharing.
- Uninstall URL hijack and install URL hijack both active — redirect manipulation pattern.
- WhatsApp brand impersonation: developer domain extensao.store is not affiliated with Meta/WhatsApp.
- 10 distinct external JS hosts on wascript.com.br/watools.com.br; function_constructor and innerHTML DOM-XSS sink in bundled JS.
Evidence
- operator_cluster_siblings api 19 sibling extensions share same dev email, install URL, CSP host set — large operator cluster.
- privacy_policy_generic_google store Privacy URL is myaccount.google.com/privacypolicy — Google's own policy, not scoped to this extension at all.
- uninstall_url_hijack crx chrome.runtime.setUninstallURL() set to 3rd-party target.
- install_url_hijack crx onInstalled opens https://web.whatsapp.com — install redirect active.
- brand_impersonation store WhatsApp brand mentioned; developer domain extensao.store not confirmed as Meta affiliate.
- js_external_hosts crx 10 distinct wascript.com.br/watools.com.br endpoints contacted; broad external network surface.
- function_constructor crx new Function() constructor found in bundled JS — dynamic code execution risk.
- privacy_policy_classification api scope_extension=false, data_collection=true, third_party_sharing=true — worst-case generic policy.
Permissions Breakdown
- unlimitedStorage low Allows unlimited local storage; low direct risk but enables large data caching.
- storage low Standard local key-value storage, minimal risk.
- alarms low Scheduling API; low risk, used for background task timing.
- tabs medium Can read tab URLs and titles; moderate risk for session awareness.
- https://web.whatsapp.com/* medium Scoped host access to WhatsApp Web only; matches stated function but enables message interception.
Pillar Scores
Permissions2.30
Reputation7.00
Network4.50
Webstore10.00
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure0.00
Operator Siblings (24)
Other extensions sharing this developer's compound fingerprint:
- cellckcnenolgakggljkichbmgmbibgb
- aocojboaoklgedadlpaallelnanhcpgm
- bgnkgembgfkfjipflkniiibgcedloekn
- bjhbgbfapjofmjcoonncefneakppmkmo
- bpgbjcgkegcecddlnlckjcoddhpmekdh
- cplaeebopfpnoebkaimlibpdickcjofa
- afdhcpnimkgccfjcelgkiipidhebddjh
- abkolnpebgghiglkkdjcgjgbpnddmfmp
- gjlfpggiddcminhebiejofeglfjmleli
- gkkkdobapmhkaihggejlcdbjemfkhdgk
- gollbfedpcfodjgfjddbkfnkkfdedknn
- hcbmcbkjjklkjidikpggmmfpfklcpnmb
- hkdbocoaofpdmbbgpimdkhcafenpkikn
- iibldfhmeiipohbjlkhfgnjhcmkknffi
- ikliliinakofoiojghnipegfphmoljla
- jeicljefnlpdoblklfdephbpihhjgphf
- jkblcpmoooocmdcfjojdecccejlkicap
- jhokpeoaapahcoaigkfnienliabeaang
- jcjodbceolndbhnbljiedcanmglmhmop
- lfenojckeamfnllggndghkmfhkheiimc
- lhadifphljjldcidjbhdpfcoemhddeec
- hdagfineacponepnaljjkkgjoddgpjld
- dkgcodmnjmlmgmdlbekkcjjjidkflnal
- hpfmfjmhhkfpcedjikogphkfacokfagh
Scoring History
| sssiedn8f7071d3dp727562726963xsx | 6.36 | High | block | 2026-09-07 |
| v3.6 | 6.27 | High | block | 2026-08-31 |
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 04:22
Listing SHA
159cf5f3f0e4…
Force block
— not fired
Score recovered
no
Elapsed
—