Run Whats Sender
pokenhlckhaoenaipopidoddgdbhlegh
Risk Score
7.38
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- browsingData + broad host access (<all_urls>) allows full browsing data deletion and page content exfil.
- Developer domain runwhats.com does not resolve; privacy policy unfetchable — no accountability.
- Three medium CVEs in bundled jquery@1.9.1 (XSS); no CSP amplifies exploitability.
- 26 months without update; stale extension with high-capability permissions is a supply-chain risk.
- Dynamic script injection + innerHTML sink with no CSP creates DOM-XSS attack surface.
Evidence
- broad_host_access manifest http://*/* and https://*/* grant read/modify on all pages; paired with browsingData and scripting.
- developer_domain_no_resolve api threat_intel: runwhats.com resolves=false; privacy policy fetch failed with ConnectionError.
- privacy_policy_unfetchable api privacy_policy_classification.fetched=false; cannot assess data handling commitments.
- cve_medium_x3_jquery crx jquery@1.9.1 carries CVE-2015-9251, CVE-2019-11358, CVE-2020-11023 (all XSS, fixed in >=3.5.0).
- no_csp_with_cve manifest csp_present=false; CVE amplifier applies — jquery XSS CVEs with no CSP protection.
- stale_extension store Last updated June 2024; 26 months_since_update triggers +8.5 maintenance score.
- dynamic_script_injection crx script_src_dynamic in app/app.js and app/content.js; dom_sink_innerhtml in content.js.
- tail_attack_surface api install_perm_anomaly: 134 installs + high-tier permissions (small_install_high_perm=true).
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@1.9.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11023 | jquery@1.9.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@1.9.1 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- activeTab low Scoped to user-initiated tab — limited risk alone.
- scripting high Programmatic script injection into pages; paired with broad host access.
- background low Persistent service worker; enables long-running operations.
- browsingData high Can delete cookies, cache, history — destructive capability.
- tabs medium Access to tab URLs/titles across all open tabs.
- http://*/* high Broad HTTP host access — can read/modify any HTTP page.
- https://*/* high Broad HTTPS host access — can read/modify any HTTPS page.
Pillar Scores
Permissions8.00
Reputation6.00
Network5.50
Webstore5.00
Maintenance8.50
Privacy10.00
Code Quality6.00
CVE Exposure4.50
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 04:57
Listing SHA
41ac625f6217…
Force block
— not fired
Score recovered
no
Elapsed
—