CRX aminer
Extension icon

WAPI FREE - Jaguar

Version 3.2.305 View in Chrome Web Store

Last scanned: about 8 hours ago

Extension Details

Developer: wapi7.com
Rating: 3.2 ★ (748 ratings)
Users: 200,000

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors:

The extension has a substantial user base of 200,000 users, which suggests some level of community acceptance. However, the relatively low rating of 3.2 out of 5 from 748 reviews indicates mixed user experiences and potential issues. The developer domain "wapi7.com" lacks clear corporate identity or established reputation, which reduces trustworthiness. The vague description and missing key metadata (size, last updated date) further diminish confidence in the extension's legitimacy.

Concerns:

The extension requests broad host permissions for WhatsApp Web, which is appropriate for its apparent WhatsApp-related functionality. However, the combination of scripting, declarativeNetRequest, and browsingData permissions creates potential for data collection beyond what's necessary for basic WhatsApp enhancement. The activeTab permission, while flagged as medium-risk, is actually reasonable for this type of extension. The high-risk finding regarding broad host permissions is somewhat mitigated since they're specifically limited to WhatsApp Web domains rather than all websites.

Recommendations:

Given the medium risk level and mixed user reviews, consider running this extension in a separate Chrome profile to isolate potential security risks. Monitor the extension's behavior closely and review what data it accesses. Consider researching alternative WhatsApp Web extensions with better ratings and more transparent developers. Regularly check for updates and user feedback to stay informed about any emerging security issues.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.