Every WhatsApp CRM extension roundup copies the same feature table off the same vendor pages. So we did something else: we downloaded the actual .crx package for 16 WhatsApp CRM Chrome extensions and read what is inside them. Three of the extensions that still appear in 2026 “best of” lists are no longer distributed by Google at all. Two of them are the same product wearing different logos.
If you search for a WhatsApp CRM extension, you get a dozen listicles that all rank the same eight tools in a slightly different order. None of them tell you the two things that actually matter before you click Add to Chrome: what the extension is allowed to read, and who is on the other end of it.
A WhatsApp CRM extension runs inside WhatsApp Web. That means it sits in the same page as every conversation you have — client names, phone numbers, quotes, invoices, ID documents people send you. There is no sandbox between it and your inbox. Choosing one on the basis of a feature grid is choosing a business partner on the basis of their logo.
So this guide is built from primary data. On 24 August 2026 we pulled every listing and, where Google still served one, the signed extension package itself, and read the manifest.json out of each. Everything below is reproducible — the method is in How to check any extension yourself, and it takes about a minute per extension.
label/.Three checks, run against 16 extensions on 24 August 2026.
1. Is it still distributed? Every Chrome extension has an ID, and Google serves updates from a single endpoint. Ask that endpoint for an extension that has been pulled and it answers HTTP 204 No Content — an empty response. Ask it for a live one and it redirects you to the actual .crx file. This is a much better liveness test than loading the store page, because the store is a JavaScript app that returns HTTP 200 whether or not the item exists.
2. What can it read? A .crx is a signed ZIP. Unzip it, open manifest.json, and read permissions and host_permissions. This is the ground truth — the store’s human-readable permission warnings are a summary of it, and marketing copy is not evidence at all.
3. Who ships it? The store listing carries the publisher name, and, where the developer has provided one, a physical address and contact email.
We are not ranking by install count. Install count tells you how many people once clicked Add to Chrome. It does not tell you whether the extension is still maintained, who is behind it, or what it can read — and those are the things you can actually verify.
These three IDs return an empty 204 from Google’s extension update service, and their store pages render no listing data. Both signals together mean the item is no longer being distributed:
| Extension | Extension ID | Update service | Store page |
|---|---|---|---|
| WA WorkFlow | gjpbfemadlcjhmadmmamocpapdacpmci | 204 — empty | no listing data |
| Whato — CRM para WhatsApp | joglkiagmlpbmicjghnmogafgdkpocdj | 204 — empty | no listing data |
| WhatsApp-Web-Plus | kgmikiogebpchdgdehpkehgnnnhpdgja | 204 — empty | no listing data |
We are not guessing at why. An extension leaves the Chrome Web Store for all sorts of reasons — the developer withdraws it, or Google removes it over a policy or security problem, or it simply stops being maintained and gets swept up in a store cleanup. Google does not publish a reason, so nobody honestly can tell you which happened.
What matters practically is this: if you already have one of these installed, it is no longer receiving updates. A WhatsApp extension that stopped being updated is a WhatsApp extension that will break the next time WhatsApp Web changes its internals — and if the reason it left was a security issue, you are still running the version that had it. Open chrome://extensions and check the IDs above against what you have installed.
There is a broader lesson for how you read any tool roundup, including this one: a review that was accurate when it was written quietly becomes wrong. Most WhatsApp extension listicles are never re-checked after publication. That is why the method matters more than the ranking, and why we have dated every number on this page.
This one we did not expect. waTidy (20,000 users) and ZAPFY CRM both report version 7.4.3.79. That is a suspiciously specific coincidence, so we unpacked both and hashed every file.
| Comparison of the two packages | Result |
|---|---|
| Version string | 7.4.3.79 in both |
| Files present in both packages | 419 |
| Byte-for-byte identical (SHA-256) | 415 of 419 |
| Files that differ | manifest.json, label/config/utils.json, label/icons/plugin/icon.png, _metadata/verified_contents.json |
| Unique to waTidy | label/css/watidy.css and three brand images |
| Unique to ZAPFY | label/css/zapfycrm.css |
| Declared permissions | identical in both |
Every difference is a name, a logo, a colour or a signature. The engine is the same engine. And the folder holding the differences is called label — as in white label.
To be precise about what this does and does not show: it shows the two listings ship the same codebase. It does not tell us the commercial arrangement behind them, and we are not suggesting anything improper — reselling software under your own brand is a completely normal, legitimate business model. It is, in fact, the model this site is built around. What is notable is simply that it is already happening in the WhatsApp CRM category and nobody mentions it, so buyers comparing “two products” are sometimes comparing one product twice.
It also explains something you may have noticed while shopping: several WhatsApp CRM extensions feel oddly similar — same Kanban layout, same quick-reply panel, same funnel screen. Sometimes that is convergent design. Sometimes, as here, it is literally the same build. The publisher email on the waTidy listing is contato@extensao.store — a domain that translates as “extension store”.
This is the table we wish existed when we started. host_permissions is the important column: it lists the sites the extension may read and modify. web.whatsapp.com only is the tightest scope a working WhatsApp CRM can have. Anything broader deserves an explanation.
| Extension | Version | Last updated | Sites it may read & change |
|---|---|---|---|
| waTidy | 7.4.3.79 | 21 Aug 2026 | web.whatsapp.com |
| WA Web Plus – Privacy Blur | 1.5.2 | 21 Aug 2026 | web.whatsapp.com |
| WhatsCRM | 1.12.6 | 5 Aug 2026 | none declared |
| Cooby | 1.89.0 | 21 Aug 2026 | *.cooby.co |
| WAWCD (Spadasoft) | 3.7.13 | 12 Aug 2026 | web.whatsapp.com, api.hubapi.com |
| WA Web Plus (Elbruz) | 5.2.1 | 2 Aug 2026 | web.whatsapp.com, wawplus.com |
| WAPlus CRM | 1.8.9 | 22 Aug 2026 | web.whatsapp.com, *.waplus.io |
| WA CRM | 2.4.0 | 12 Jan 2026 | web.whatsapp.com, app.coderlicences.com |
| WACRM (Cloodo) | 1.1.0 | 16 Nov 2024 | *.whatsapp.com, worksuite.cloodo.com |
| ZapFlow | 4.0.11 | 29 Jul 2026 | web.whatsapp.com, zapflowapp.com.br, *.amazonaws.com |
| ChatFlow | 1.9.0 | 21 Apr 2026 | web.whatsapp.com, Firebase, Google APIs |
| Lion CRM | 5.10 | 20 Aug 2026 | <all_urls> — explained below |
Three things to take from this.
WACRM has not been updated since November 2024. It is still listed, still installable, and still asks for access to your WhatsApp. Twenty-one months without a release, in a product category that depends on tracking WhatsApp Web’s internals, is a long time. Being present in the store is not evidence of being maintained.
“None declared” is not the same as “safe”. WhatsCRM declares no host permissions in its manifest, which means the parts of it that touch your data are doing so another way — typically by asking for access at runtime. It is not a red flag by itself; it just means the manifest cannot tell you the answer and you should look at what the extension asks for when you first use it.
An extra host is not automatically bad. WAWCD lists api.hubapi.com because it integrates with HubSpot. ZapFlow lists its own API and an AWS bucket. Those are functional. The question to ask is whether the extra host has an obvious reason to be there — and whether the vendor tells you what it is.
If an extension mishandles your customer data, your recourse depends entirely on there being someone to hold responsible. The Chrome Web Store shows you exactly how much the publisher has chosen to reveal.
| Extension | Publisher as listed | Traceable? |
|---|---|---|
| Cooby | Navis One Lab, LLC — Dover, DE, US | Registered company + address |
| WAWCD | WAWCD LLC — Austin, TX, US | Registered company + address |
| WA Web Plus (Elbruz) | Elbruz Technologies — Istanbul, TR | Company + address |
| WACRM | Netbase JSC — Ha Noi, VN | Company + address |
| Lion CRM | Kuldeep Dadhich — address listed | Named individual + address |
| waTidy | contato@extensao.store | Email only |
| WAPlus CRM | personal Gmail address | Email only — no company |
| WA Web Plus – Privacy Blur | personal Gmail address | Email only |
| WA CRM | personal Gmail address | Email only |
| ZapFlow | personal Hotmail address | Email only |
| ChatFlow | personal Gmail address | Email only |
| WhatsCRM | company-domain email | Email only |
The line worth pausing on: WAPlus CRM has around 70,000 users and lists a personal Gmail address with no company entity behind it. It is a polished, frequently updated, well-reviewed extension — a 4.9 average and a release eight days before we measured. We are not accusing it of anything. But 70,000 businesses have given read access to their WhatsApp inbox to a party whose only published identity is a free email account, and if that ever goes wrong there is nobody to serve notice on.
We have deliberately not reproduced the individual email addresses here. They are on the public listings and you can read them yourself in a few seconds — the point is not to expose anyone, it is that you should look before you install.
If you are handling customer data under GDPR, India’s DPDP Act, or an equivalent, this column is not a curiosity. A processor you cannot identify is a processor you cannot lawfully appoint.
It would be easy to publish the table above and leave our own row out of it. Here it is instead, in full, because a permissions audit that exempts the author is not an audit.
Lion CRM requests <all_urls> — the broadest host permission in this entire comparison. When you install it, Chrome will tell you it can “read and change all your data on all websites”. That is a fair description of the permission, and if it gives you pause, good — it should.
Here is what is actually in the manifest, and you can verify all of it yourself:
| Field | Value |
|---|---|
| Manifest version | MV3 |
host_permissions | <all_urls> |
| Content scripts run on | *://*.whatsapp.com/* only |
permissions | storage, unlimitedStorage, tabs, scripting, alarms, notifications, management |
The distinction that matters is between host_permissions and content_scripts. The code Lion CRM injects into web pages is scoped to WhatsApp domains and nothing else — that line is in the manifest, it is short, and it is the part that governs what actually runs on the pages you browse. Lion CRM does not inject anything into your bank, your email or your CRM.
The broad host_permissions entry exists because of the features that talk to endpoints we cannot know in advance: webhooks and custom API configuration. If you point Lion CRM at your own webhook, the extension has to be allowed to reach a URL that only you know. Chrome has no way to express “whatever host the user types into settings later”, so the manifest asks for the general case.
That is the honest explanation, and it is also a fair thing to push back on. A tighter design would request the narrow scope up front and ask for the broad one only when you switch webhooks on. We would rather tell you that than pretend the permission is not there.
management deserves its own note: it lets an extension see the other extensions you have installed. In Lion CRM it is used for license and conflict checks — several WhatsApp extensions fight over the same page and detecting that is how you get a useful error instead of a blank screen. It is still a permission most WhatsApp CRMs in this table do not request. Cooby is the only other one here that does.
Judge the whole table on the same standard, ours included. That is the point of publishing it.
Do not take our word for any of the above — and more importantly, do not take a listicle’s word for it six months from now, when the numbers have moved. Here is the whole method.
Step 1 — get the ID. It is the 32-letter string in the store URL: chromewebstore.google.com/detail/<name>/abcdefgh.... For something already installed, open chrome://extensions and turn on Developer mode.
Step 2 — is it still alive? Paste this into your browser, with the ID substituted in:
https://clients2.google.com/service/update2/crx?response=redirect&prodversion=128&acceptformat=crx3&x=id%3DTHE_ID%26uc
If a .crx file downloads, the extension is live. If you get an empty response, Google is no longer distributing it — that is exactly the check that surfaced the three dead extensions above.
Step 3 — read the manifest. Rename the downloaded .crx to .zip, open it, and read manifest.json. Look at host_permissions (what it may read), content_scripts → matches (where its code actually runs), and permissions. If host_permissions is broad but content_scripts is narrow, ask the vendor why — there is often a legitimate answer, and a vendor who cannot give you one has told you something.
Step 4 — look at the publisher. Scroll to the bottom of the store listing. A company name and address is meaningfully better than an email address on a free mail provider.
That is it. Four steps, and it works for any Chrome extension, not just WhatsApp ones.
A ranked list would be dishonest here, because the right answer depends on what you are doing. What we can do is match the data to situations.
If you want the tightest possible permission scope, the extensions restricted to web.whatsapp.com alone — waTidy and WA Web Plus – Privacy Blur — ask for the least. Remember that waTidy is the build that also ships as ZAPFY.
If you need someone accountable, the four publishers with a registered company and a street address — Cooby, WAWCD, Elbruz, Netbase — are the ones you can actually put in a data processing agreement.
If you need a full pipeline inside WhatsApp Web — Kanban stages, follow-up sequences, bulk campaigns, AI replies — that is the category Lion CRM, WAPlus and WAWCD compete in, and it is worth reading our 2026 WhatsApp CRM software buyer’s guide alongside this page, because at that level of complexity the WhatsApp Business API becomes a real alternative to an extension.
If you are comparing Lion CRM with waTidy specifically, we have a feature-by-feature comparison of the two.
Whatever you pick, run Step 2 above first. It costs a minute and it is the check that would have saved anyone who installed WA WorkFlow on the strength of a 2026 listicle.
The waTidy/ZAPFY finding is the most useful thing on this page for one particular reader: the agency or IT company that wants its own WhatsApp CRM product rather than a referral commission.
What that byte comparison shows is that shipping the same WhatsApp CRM engine under two brands is already routine in this category. The build carries a label/ folder holding a stylesheet, an icon and a config file, and swapping those three things produces a second product. That is the entire technical shape of a whitelabel arrangement.
The difference between doing that and being a reseller of someone else’s brand is margin and ownership. An affiliate program pays you a percentage once. A whitelabel license lets you set your own pricing, own the customer relationship, and keep renewals.
Lion CRM is available on exactly that basis — your brand, your pricing, your customers, with the extension published under your identity. If that is what brought you here, these are the pages you want:
All extension data on this page — store listings, versions, last-updated dates, publisher details and manifest permissions — was measured on 24 August 2026 by requesting each extension from Google’s Chrome Web Store and extension update service and reading its manifest.json. Chrome extensions change frequently; re-run the checks in How to check any extension yourself before relying on any figure here.
Browse every guide in the complete Lion CRM article index, or start from the Lion CRM blog.