MkZap
ogckebjiloagfejjlfbengnojollodok
Risk Score
4.23
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- WhatsApp impersonation: brand_mention.is_impersonation=true, dev is unverified gmail user with no confirmed ownership.
- Content script injected into WhatsApp Web can read all messages and UI; combined with no CSP.
- Privacy policy fetched but scope_extension=false and data_collection=false — not scoped to this extension; +9.0 privacy.
- Free-webmail developer (ivanilopes790@gmail.com) with no verified business identity raises accountability risk.
- install_url_hijack opens web.whatsapp.com on install; onInstalled 3rd-party URL pattern.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true for 'whatsapp'; developer domain is gmail.com, confirmed_owner=false.
- free_webmail_developer store Developer email ivanilopes790@gmail.com; no business website; developer_name='ext.user001'.
- privacy_policy_not_extension_scoped api Policy fetched; scope_extension=false, data_collection=false — generic hiperchat.com.br policy, not extension-specific.
- content_script_sensitive_origin manifest Content script injected into https://web.whatsapp.com/* — full access to WhatsApp Web DOM and messages.
- dom_xss_sink crx innerHTML assignment from variable in vendor.DzFEYc3-.js with no CSP; DOM-XSS risk on WhatsApp origin.
- install_url_hijack manifest install_url_hijack=true; onInstalled opens https://web.whatsapp.com — 3rd-party URL pattern.
- no_csp manifest content_security_policy=null; MV3 defaults apply but no explicit CSP; dom_sink finding elevated.
- js_external_hosts crx External JS hosts: hc-stt.hiperchat.com.br, reactjs.org, web.whatsapp.com — 2 distinct registrable domains.
Permissions Breakdown
- unlimitedStorage low Allows unbounded local storage; low direct threat but enables large local data accumulation.
- storage low Standard local data persistence; low risk in isolation.
- tabs medium Can read tab URLs and titles; moderate surveillance potential.
- alarms low Scheduling only; no direct data access.
- content_scripts:https://web.whatsapp.com/* medium Injected into WhatsApp Web — can read/modify all messages and user data on that origin.
Pillar Scores
Permissions2.30
Reputation7.50
Network2.00
Webstore3.50
Maintenance1.50
Privacy9.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 16:00
Listing SHA
5cf2d0e20f53…
Force block
— not fired
Score recovered
no
Elapsed
—