Caution required
Suspicious in code review (v5.4.420)
Our reviewer found behaviour consistent with malware in version 5.4.420, but not enough to confirm it. Treat this extension as untrusted until it has been re-reviewed.
49 indicators in this extension
Every finding is verified by a security analyst. Unlock the code evidence, indicators and version history.
What our analysis found
WAPI PREMIUM 5.4.302 - Jaguar, used by 10,000 people, is rated caution by Extension Auditor. Our code review reported 3 findings (2 high, 1 medium), led by network interception. Its permissions mean it can inject scripts into pages.
Key findings
- High
Network Interception
disableCSP() installs a declarativeNetRequest session rule that sets the Content-Security-Policy response header to the empty string for the current tab's URL, and it is invoked unconditionally from chrome.tabs.onActivated (:152-155) for every tab the user switches to, not just [domain withheld]. Combined with the [domain withheld] and [domain withheld] host permissions, browsing to any site and activating its tab permanently disables that site's CSP for the session, removing its primary defence on origins entirely unrelated to the extension's stated WhatsApp purpose. The same path calls chrome.browsingData.remove({}, {serviceWorkers: true}) with empty options, which wipes registered service workers for all origins and all time, not only for WhatsApp.
- High
Remote Code Loading
is injected into WhatsApp Web's main world as a <script src> tag (:405-406), and it dynamically import()s an ES module from the remote host [domain withheld], so third-party code fetched at runtime executes with full access to the logged-in WhatsApp Web session. This is remote code loading that Manifest V3 is designed to prevent, and it only succeeds because the extension's background service worker blanks the page's Content-Security-Policy; a compromise or change of that CDN would translate directly into arbitrary code running inside every user's WhatsApp session. The resulting visitorId is used for licence device binding, which does not require executing remote code rather than the bundled
- Medium
Other
dump() is called at line 402 against [domain withheld], a personal third-party GitHub repository that is not the publisher's [domain withheld] infrastructure, and the fetched value gates the extension's runtime state ('stp' versus 'rn'). This is a remote control channel whose owner can change extension behaviour for all 10,000 users without a Chrome Web Store update and without publisher involvement. It does not fetch executable code, which caps the severity, but the dependency on an unrelated third party for runtime control is not justified by the extension's stated purpose.
Analyst notes
The extension does what its listing says: a WhatsApp Web bulk sender injected only into *.[domain withheld], whose only network calls (:, all to [domain withheld]) carry the user's own WAPI account credentials plus a FingerprintJS device id for binding, matching the CWS-disclosed 'Authentication information' and the [domain withheld] publisher backend; no WhatsApp contacts, chats or page content are sent anywhere in the code I reviewed, and the bundled manifest matches the published manifest exactly. What keeps it out of 'benign' is real collateral damage unrelated to WhatsApp::152 fires disableCSP() on every tab activation, and with [domain withheld] + [domain withheld] host permissions that installs a declarativeNetRequest rule blanking Content-Security-Policy on whatever arbitrary site the user switches to, while also calling chrome.browsingData.remove({}, {serviceWorkers:true}) for all origins; that stripped CSP is exactly what lets:254 dynamically import() a third-party ES module from [domain withheld] into WhatsApp Web's main world. Signals: the ML score is driven by the permhash cluster (52% flagged, a WhatsApp-automation cluster) and the malext feed row, which itself states it is not an independent code review, while the Google trusted-publisher badge, malicious sibling extensions and chrome-stats contradict it; the ML regex hits are accounted for in vendored code (all are in and, the innerHTML volume is the injected panel template in, and there is no eval in custom code). Confidence is medium, not high, because the bundle is incomplete: is loaded at:406 but absent, and the #WAXP_EXPORT contact-exporter handler exists in no reviewed file, so the contact-extraction and WA-JS layers were not reviewed. Hygiene issues not logged as findings: the account password is stored in plaintext localStorage on the [domain withheld] origin (:1533), a GitHub kill switch at:402 fetches [domain withheld] but only writes the text 'stp'/'rn', is dead code (the manifest's service worker is), and the hex filenames decode to author tags ('owned snurf', 'app snurf corp'), not anti-analysis packing.
WAPI PREMIUM 5.4.302 - Jaguar Chrome extension security report
ID: cijobdncciemcimkomiehfanikkldjej
Supported Languages
Extension Info & Metadata
Publisher Contextual Analysis
- Author
- https://wapi7.com
- Privacy
- Privacy Policy
- Help
- Help Center
- MX records exist
- Yes
- Domain exists
- Yes
- Is disposable
- No
- Is role-based
- No
- Mailbox exists
- Yes
- Website
- Visit
Screenshots & videos
Install growth
49 indicators in this extension
Every finding is verified by a security analyst. Unlock the code evidence, indicators and version history.
About this extension
Send personalized messages to your clients with our extension .
Read the publisher’s full description
Best WhatsApp Sender Application - WAPI * Send messages to unlimited numbers * Support : images, videos, documents .. * Random Delay between messages * Import numbers fron .CSV file * Download cvs shipping reports * Support Variables * Custom fields for messages * Messages with emojis * Contact extractor * Chat extractor * Groups contact extractor WAPI ★ WAPI allows you to send automated, customized, bulk, WhatsApp messages. By doing this, you can have meaningful conversations with your clients and target audience thereby growing your business. ★ No more one by one sending off messages to all your customers. ★ No more sending of common messages to your prominent users. LEGAL DISCLAIMER: This Chrome plugin is not endorsed or certified by WhatsApp Inc and is merely an unofficial enhancement and automation tool that works with WhatsApp for Web. The privacy of the users is important to us. We don’t broadcast, sell, share or distribute any user collected data. The extension was designed to keep privacy of our users in mind. For more information, read: WAPI PREMIUM privacy policy: https://www.wapi7.com/terms WAPI PREMIUM privacy policy: https://www.wapi7.com/terms Razorpay privacy policy: https://www.wapi7.com/terms Note : This is not an official extension of WhatsApp. WhatsApp is a trademark of WhatsApp Inc. , registered in the U.S. and other countries. This Chrome extension is not endorsed or certified by WhatsApp Inc. This is an unofficial enhancement for WhatsApp Web.
User reviews
Extension files
Browse and explore files within this extension package
Gain full insight into all external connections.
Upgrade for full visibility.
URLs
View the external URLs this extension communicates with to understand its network activity and data interactions.
49 indicators in this extension
Every finding is verified by a security analyst. Unlock the code evidence, indicators and version history.
Code Diff
Compare extension code between any two versions.
0 changed files detected
No comparable text files found between these versions.
Gain full insight into all external connections.
Upgrade for full visibility.
Related extensions
Popular in lifestyle/social
- Skype3,000,000 users
- Skype Calling2,000,000 users
- Não Seguidores1,000,000 users
- Google Meet Tweak (Emojis, Text, Cam Effects)900,000 users
- VidyoWebConnector600,000 users