WA BOOSTER
olmbfmmlpodikepicechoekmiiejpmel
Risk Score
5.38
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's own policy (not scoped to this extension); admits data collection and 3rd-party sharing → Privacy pillar 10.0.
- Uninstall URL hijack and install URL hijack both flagged; redirects users on lifecycle events.
- WhatsApp brand impersonation by unverified developer (extensao.store) with no confirmed ownership.
- 10 external JS hosts under wascript.com.br/watools.com.br contacted at runtime with no CSP; broad attack surface.
- function_constructor (new Function) in content script running on WhatsApp Web enables dynamic code execution.
Evidence
- privacy_policy_generic store Privacy policy URL is Google's account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 rule D).
- uninstall_url_hijack crx uninstall_url_hijack=true; install_url_hijack=true targeting https://web.whatsapp.com → +3.0 webstore (install) +3.0 (uninstall).
- brand_impersonation store brand_mention.is_impersonation=true for 'whatsapp'; developer domain extensao.store not confirmed owner → +2.0 reputation.
- external_js_hosts crx 10 distinct wascript.com.br/watools.com.br endpoints in js_external_hosts; >3 distinct domains → +1.5 network.
- no_csp crx csp_present=false on MV3 extension with external hosts and DOM sink; dom_sink_innerhtml_userctrl promoted to +2.0 per FIX B.
- function_constructor crx new Function() constructor found in content script running on WhatsApp Web → +2.5 code quality (debugger_attach/function_constructor tier).
- unverified_developer store verified_publisher=false, is_featured_by_google=false, dev name 'wsll' minimal identity → reputation starts 5.0 +2.0 impersonation.
- install_count_low store Only 67 installs; installs thresholds not triggered. Rating=5 but rating_count not supplied, no -0.5 discount applied.
Permissions Breakdown
- unlimitedStorage low Allows unbounded local storage; low risk alone but could cache exfiltrated data.
- storage low Standard key-value store; low risk.
- alarms low Scheduling API; minimal risk.
- tabs medium Can read tab URLs and titles; medium risk when combined with WhatsApp host access.
- https://web.whatsapp.com/* medium Scoped host access to WhatsApp Web; content scripts can read all messages on that origin.
Pillar Scores
Permissions2.30
Reputation7.00
Network3.50
Webstore8.00
Maintenance0.00
Privacy10.00
Code Quality4.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 16:58
Listing SHA
ba2c50fcc2ed…
Force block
— not fired
Score recovered
no
Elapsed
—