Nextgo Zap: Seu Whatsapp Turbinado!
pdlpnkplaofpdajmgegfnlifmdlejmfp
Risk Score
5.11
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's own policy — not scoped to this extension; admits data collection and third-party sharing (Privacy +10.0).
- Uninstall URL hijack and install URL hijack both flagged; onInstalled redirects to web.whatsapp.com (Webstore +3.0+2.0).
- WhatsApp brand impersonation by unverified developer 'Intzp' on extensao.store domain (Reputation +2.0).
- 9 distinct external wascript.com.br/watools.com.br endpoints contacted; broad network surface for a 438-install CRM tool.
- new Function() constructor found without CSP — dynamic code execution risk on WhatsApp Web content.
Evidence
- uninstall_url_hijack + install_url_hijack crx Both uninstall and install URL hijacks set; install redirects to https://web.whatsapp.com.
- generic_privacy_policy store Privacy URL is Google's generic policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0.
- brand_impersonation store WhatsApp brand mentioned; developer not confirmed owner; is_impersonation=true, unverified publisher.
- js_external_hosts crx 10 distinct wascript.com.br / watools.com.br subdomains contacted; >3 registrable domains.
- function_constructor crx new Function() detected in JS bundle without CSP; dynamic code execution risk.
- dom_sink_innerhtml_userctrl crx innerHTML sink from variable with no CSP present; DOM-XSS risk elevated to +2.0.
- no_csp crx content_security_policy is null; MV3 default applies but no explicit restriction on eval/remote scripts.
- developer_identity store Developer 'Intzp' at extensao.store; not verified publisher, not featured, 438 installs.
Permissions Breakdown
- unlimitedStorage low Local storage expansion; low direct risk but enables large local data caching.
- storage low Standard extension key-value storage; low risk.
- alarms low Scheduling alarms; low risk, could enable periodic background tasks.
- tabs medium Access to tab metadata and URLs; medium risk when combined with host permissions.
- https://web.whatsapp.com/* medium Scoped host permission to WhatsApp Web; allows full page content read/write on that domain.
Pillar Scores
Permissions1.60
Reputation7.00
Network4.00
Webstore8.00
Maintenance0.00
Privacy10.00
Code Quality4.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 17:05
Listing SHA
c55a67ab0a71…
Force block
— not fired
Score recovered
no
Elapsed
—