Plusfy
pdjlogbgaodpgdlpmikbopjbhabebifb
Risk Score
4.03
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- Content script on web.whatsapp.com grants full DOM access to WhatsApp messages and contacts.
- Privacy policy is Google's generic policy — not scoped to this extension; admits data collection and 3rd-party sharing.
- Uninstall and install URL hijacks detected; install redirects to web.whatsapp.com.
- WhatsApp brand impersonation by unverified developer — not a Meta-affiliated publisher.
- Multiple wascript.com.br backend endpoints plus 309 JS files with function_constructor and innerHTML sinks; no CSP.
Evidence
- content_script_whatsapp manifest content_scripts_matches=[https://web.whatsapp.com/*] — full DOM access to WhatsApp Web including messages.
- privacy_policy_generic_google store PP URL is myaccount.google.com/privacypolicy — Google's policy, scope_extension=false, data_collection=true, third_party_sharing=true.
- uninstall_url_hijack crx chrome.runtime.setUninstallURL() present; install_url_hijack opens https://web.whatsapp.com on install.
- brand_impersonation_whatsapp store brand_mention.is_impersonation=true for WhatsApp; developer domain covertlab.com.br, confirmed_owner=false.
- external_backend_hosts crx 8 distinct wascript.com.br/waclientes.com.br endpoints plus mail.google.com contacted; no CSP present.
- function_constructor_no_csp crx new Function() constructor used in content JS with csp_present=false — arbitrary code execution risk.
- dom_sink_innerhtml_no_csp crx innerHTML assigned from variable in content script; csp_present=false and eval-class finding present → elevated DOM-XSS risk.
- react_16_13_1_bundled crx React 16.13.1 bundled (below 16.4 threshold noted in rules); no CVEs found in cve_findings_raw.
Permissions Breakdown
- unlimitedStorage low Can store large amounts of data locally; low sensitivity on its own.
- storage low Standard local/sync key-value storage; routine.
- alarms low Allows scheduled callbacks; minimal risk alone.
- tabs medium Can enumerate tab URLs/titles; combined with WhatsApp content script raises sensitivity.
- content_scripts_matches: https://web.whatsapp.com/* high Full DOM access on WhatsApp Web — can read messages, contacts, and inject UI.
Pillar Scores
Permissions2.10
Reputation6.00
Network3.50
Webstore7.50
Maintenance3.50
Privacy10.00
Code Quality4.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 05:36
Listing SHA
aa2c4305452c…
Force block
— not fired
Score recovered
no
Elapsed
—