Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeAI Agent for WhatsApp
Findings · 3
MEDIUM FINDINGS · 3
  1. 01WA-JS bundle ships a hardcoded Google Analytics 4 tracker (G-MTQ4KY110F) that is left enabled and reports WhatsApp Web events (page_view, login, exception, user_engagement) plus the WhatsApp Web version as a user property to analytics.google.com.
  2. 02Extension features (export contacts, export chats, export group members, broadcast, status download) run via window.postMessage handlers in the content script with no origin or source-window check, allowing any script with execution on web.whatsapp.com to invoke high-value data-export and broadcast actions.
  3. 03Extension reads user contact list, full chat list, group memberships, and status posts from WhatsApp Web and forwards them to the popup UI via chrome.runtime messaging.
OTHER EXTENSIONS

Is AI Agent for WhatsApp safe?

Medium risk

No summary available.

Mustafa Alpayv20260311011456Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026net.alpay.aiAgentwa.Extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact