WhatsApp AI Writer
pfbaaiabnelbhonjhjhdbihdigkehoml
Risk Score
6.71
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Critical CVE-2021-23358 (arbitrary code execution) in bundled underscore@1.8.3, unfixed; no CSP amplifies risk.
- Content script injected into Gmail (mail.google.com) not disclosed as part of stated WhatsApp AI function — scope mismatch.
- Privacy policy is generic Google account policy — does not scope to this extension; data collection and 3rd-party sharing admitted.
- WhatsApp brand impersonation by unverified gmail.com developer with no developer name or business identity.
- Unknown third-party backend (whatsback-production.up.railway.app + whats-back-seven.vercel.app) could exfiltrate WhatsApp/Gmail content.
Evidence
- critical_cve crx underscore@1.8.3 has CVE-2021-23358 (critical ACE); fixed in 1.12.1. No CSP present — CVE amplifier applies.
- content_script_scope_mismatch manifest content_scripts_matches includes mail.google.com but extension is described as WhatsApp-only tool.
- generic_privacy_policy store Privacy policy points to Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- brand_impersonation store WhatsApp brand mentioned; confirmed_owner=false, developer is gmail.com personal account with no dev name.
- unknown_third_party_backend manifest host_permissions include whatsback-production.up.railway.app; js_external_hosts include whats-back-seven.vercel.app.
- function_constructor_eval crx Multiple new Function() calls in bundled node_modules (ajv, vite, source-map-js) + eval_user_input in vite.
- free_webmail_dev_no_name store Developer email pachecx35@gmail.com; developer_name empty; no verified publisher badge.
- ai_extension_page_content store AI extension with content scripts on WhatsApp and Gmail processes sensitive message content.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- identity low OAuth token access; low risk without scopes specified.
- host:https://web.whatsapp.com/* medium Full access to WhatsApp Web — reads messages and DOM.
- host:https://whatsback-production.up.railway.app/* medium Unknown third-party backend on railway.app; data exfil surface.
- content_script:https://mail.google.com/* high Runs JS in Gmail — not declared in host_permissions; scope mismatch vs stated WhatsApp function.
- content_script:https://web.whatsapp.com/* medium Matches stated function; can read/write WhatsApp messages.
Pillar Scores
Permissions5.00
Reputation8.00
Network4.50
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure7.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-15 12:53
Listing SHA
06bf1111c448…
Force block
— not fired
Score recovered
no
Elapsed
—