Is "WACA 後台網址轉換器" on Chrome Web Store Safe to Install?

[email protected] · chrome · v1.2.2

此擴充工具能夠自動將使用 WACA 建立的電商平台前台網址轉換為對應的後台編輯頁面連結,讓使用者可以快速進入管理介面。 - 輸入框可自動偵測目前分頁網址,也可手動貼上 - 當網址可被轉換時會顯示「進入後台」按鈕 ✅ 支援的轉換類型: 商品頁 → /product/detail/123 → https://admin.waca.ec/products/update/123 分類頁 → /category/456 → https://admin.waca.ec/products/categorydetail/456 部落格頁 → /blog/789 → https://admin.waca.ec/blogs/update/789 ****1.2.2 版本更新****** - 主題配色更新 - 新增雙向網址轉換,支援前台與後台網址互轉 - 新增批次開啟商品後台功能,一鍵開啟頁面所有商品後台連結 - 新增設定選項,可啟用/停用批次開啟功能、是否在新頁面開啟

Risk Assessment

Analyzed
45.22
out of 100
MEDIUM

13 security findings detected across all analyzers

Chrome extension requesting 4 permissions

Severity Breakdown

0
Critical
2
High
11
Medium
0
Low
0
Info

Finding Categories

2
Malware Signatures
10
IoC Indicators

YARA Rules Matched

2 rules
postinstall system command postinstall crypto operations

Requested Permissions

4 permissions
https://*/*
Dangerous
tabs
Medium
storage
Low
scripting
Low

About This Extension

此擴充工具能夠自動將使用 WACA 建立的電商平台前台網址轉換為對應的後台編輯頁面連結,讓使用者可以快速進入管理介面。 - 輸入框可自動偵測目前分頁網址,也可手動貼上 - 當網址可被轉換時會顯示「進入後台」按鈕 ✅ 支援的轉換類型: 商品頁 → /product/detail/123 → https://admin.waca.ec/products/update/123 分類頁 → /category/456 → https://admin.waca.ec/products/categorydetail/456 部落格頁 → /blog/789 → https://admin.waca.ec/blogs/update/789 ****1.2.2 版本更新****** - 主題配色更新 - 新增雙向網址轉換,支援前台與後台網址互轉 - 新增批次開啟商品後台功能,一鍵開啟頁面所有商品後台連結 - 新增設定選項,可啟用/停用批次開啟功能、是否在新頁面開啟

Detailed Findings

3 total

YARA Rule Matches

2 rules

Indicators of Compromise

Network indicators, suspicious strings, and potential IoCs extracted during analysis

URLs
5
IP Addresses
1
Domains
4
Strings
10

All Indicators · 10

IP
detected IP: ::

XIOC detected IP: ::

extracted_from_files

URL
detected URL: https://admin.waca.ec/products/categorydetail/$

XIOC detected URL: https://admin.waca.ec/products/categorydetail/$

extracted_from_files

URL
detected URL: https://admin.waca.ec/blogs/update/$

XIOC detected URL: https://admin.waca.ec/blogs/update/$

extracted_from_files

Domain
detected Domain: clients2.google.com

XIOC detected Domain: clients2.google.com

extracted_from_files

Domain
detected Domain: www.w3.org

XIOC detected Domain: www.w3.org

extracted_from_files

Domain
detected Domain: admin.waca.ec

XIOC detected Domain: admin.waca.ec

extracted_from_files

Domain
detected Domain: currenttab.id

XIOC detected Domain: currenttab.id

extracted_from_files

URL
detected URL: https://clients2.google.com/service/update2/crx

XIOC detected URL: https://clients2.google.com/service/update2/crx

extracted_from_files

URL
detected URL: http://www.w3.org/2000/svg

XIOC detected URL: http://www.w3.org/2000/svg

extracted_from_files

URL
detected URL: https://admin.waca.ec/products/update/$

XIOC detected URL: https://admin.waca.ec/products/update/$

extracted_from_files

Security Analysis Summary

Security Analysis Overview

WACA 後台網址轉換器 is a Chrome Web Store extension published by [email protected]. Version 1.2.2 has been analyzed by the Risky Plugins security platform, receiving a risk score of 45.22/100 (MEDIUM risk) based on 13 security findings.

Risk Assessment

This extension presents moderate security risk. Several findings were detected that may warrant attention. Users should carefully review the permissions and findings before installation.

Findings Breakdown

  • High: 2 finding(s)
  • Medium: 11 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

WACA 後台網址轉換器 is published by [email protected] on the Chrome Web Store marketplace.

Recommendation

Exercise caution with this extension. Review the detailed findings and ensure the requested permissions align with the extension's stated functionality before installation.

Frequently Asked Questions