Seems to me that Whatsapp should be able to rate-limit these requests and work to secure the interface so only the legit website can actually pull the info?
The initial website display comes from a QR code you can on your phone, which the website then gets authorized by. Could they not then limit queries to that account?
I could be way off the mark, but it seems to me like the worst of this could be mitigated quite easily without much loss in functionality for users?