WAPremium MultiWeb
pjlcincdocmbnfjhgbklmagilpmdefdo
Risk Score
4.49
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic policy — not scoped to this extension; admits data collection and third-party sharing (Privacy +10).
- Uninstall and install URL hijack flags set — classic monetization/tracking pattern (Webstore +3).
- WhatsApp brand impersonation: confirmed_owner=false, is_impersonation=true (Reputation +2).
- 12 external JS hosts across 4 countries including pay.roote.com.br and painel.wapremium.com.br — broad network surface (Network +1.5).
- No developer name listed and missing 'Offered by'; verified publisher but no name increases identity opacity (Reputation +1).
Evidence
- privacy_policy_generic store Policy URL is Google's own account policy (myaccount.google.com); scope_extension=false, data_collection=true, third_party_sharing=true → +10 Privacy (D rule).
- uninstall_and_install_url_hijack crx Both uninstall_url_hijack and install_url_hijack are true; targets null but pattern is monetization shell (+3 Webstore).
- brand_impersonation_whatsapp store brand_mention.is_impersonation=true, confirmed_owner=false; WhatsApp brand used without authorization (+2 Reputation).
- external_hosts_count crx 12 distinct external JS hosts including pay.roote.com.br, painel.wapremium.com.br, socket.io, contate.ai across 4 countries.
- geo_diversity crx host_geo_diversity country_count=4 (BR, CA, DE, US); category not VPN/Adblock/Translation → +1.5 Network.
- dom_xss_sink crx innerHTML user-controlled sink in assets/3825.js; CSP present so +0.5 not +2.0 escalation.
- verified_publisher store verified_publisher=true; -3.0 Reputation but no brand-owner confirmation and no developer name listed.
- no_developer_name store developer_name is empty string; increases identity opacity (+1.0 Reputation).
Permissions Breakdown
- storage low Local data persistence; no cross-origin data exposure.
- tabs medium Can read tab URLs and titles; moderate surveillance potential.
- content_scripts: https://web.whatsapp.com/* medium Injects JS into WhatsApp Web; can read messages and DOM content.
Pillar Scores
Permissions2.30
Reputation5.50
Network3.50
Webstore7.50
Maintenance0.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 04:46
Listing SHA
30162f6955ee…
Force block
— not fired
Score recovered
no
Elapsed
—