CRX aminer
Extension icon

Contact Saver for WhatsApp

Version 1.2.11 View in Chrome Web Store

Last scanned: about 5 hours ago

Extension Details

Developer: watools.im
Rating: 4.9 ★ (992 ratings)
Users: 20,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension has a strong user base of 20,000 users with an excellent 4.9-star rating from nearly 1,000 reviews, suggesting positive user experiences. However, the developer "watools.im" lacks clear company information or established reputation, which raises some transparency concerns. The specific focus on WhatsApp contact management appears legitimate given the extension's purpose.

Concerns:

The tabs permission is excessive for a contact saving tool - this allows the extension to monitor and manipulate all browser tabs, not just WhatsApp. While the host permissions are appropriately restricted to WhatsApp domains, the combination of tabs access with scripting capabilities creates potential for broader surveillance beyond the stated functionality. The storage permission, while necessary for saving contacts, could be used to collect and retain user data indefinitely.

Recommendations:

Consider running this extension in a separate Chrome profile to isolate it from your other browsing activities. Before installation, verify that the contact saving functionality truly requires tab-level access by checking if similar extensions operate with more limited permissions. Monitor the extension's behavior after installation and revoke permissions if you notice unexpected tab interactions. Given the high rating and user base, the extension likely functions as advertised, but the excessive permissions warrant caution for privacy-conscious users.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.