Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Wombat - Gaming Wallet for Ethereum & EOS

amkmjjmmflddogmhpjloimipbofnfjih
Risk Score
2.96
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Security
Installs 30,000
Rating 4.0
Last updated 2026-04-03 (2 months ago)
Manifest version MV3
CSP present ✅ yes
Developer support@getwombat.io
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Content script injected on <all_urls> gives wallet broad page-level read access across every site visited.
  • Privacy policy fetched but does not scope to this extension or disclose data collection — privacy gap.
  • Dropbox API host permission non-obvious for a wallet; backup scope not clearly documented.
  • innerHTML DOM-XSS sink in options.bundle.js; low severity given CSP but worth hardening.
  • Geo-diverse JS hosts (DE/IN/SG/US, 4 countries) raises supply-chain surface area slightly.

Evidence

  • content_scripts_matches <all_urls> manifest Extension injects into every page; broad reach expected for Web3 wallet but elevates permissions risk.
  • privacy_policy_scope_extension=false, data_collection=false crx Policy fetched but does not reference this extension or describe its data handling → +9.0 privacy.
  • dom_sink_innerhtml_userctrl crx options.bundle.js uses innerHTML from variable; CSP present limits exploitability.
  • host_geo_diversity country_count=4 crx JS external hosts span DE, IN, SG, US — 4 countries triggers +1.5 network geo penalty.
  • no bad_host / affiliate / monetization hits api threat_intel all clear; developer domain resolves, not throwaway, no siblings.
  • cve_findings_raw empty crx No known-CVE libraries detected; CVE pillar = 0.0.
  • months_since_update=2 store Updated April 2026; maintenance risk = 0.
  • unverified_publisher + no featured badge store No verified publisher or featured badge; reputation starts at 5.0 with no positive offsets.

Permissions Breakdown

  • tabs medium Can read tab URLs and titles; medium risk for a wallet extension.
  • storage low Local data persistence; standard for wallet state.
  • clipboardWrite medium Can write to clipboard; acceptable for copy-address wallet UX.
  • notifications low Push notifications; low risk, typical for tx alerts.
  • identity low OAuth identity API without scopes; limited exposure.
  • offscreen low Offscreen document for background tasks; no elevated capability.
  • content_scripts <all_urls> high Injects into every page; broad reach for a crypto wallet injecting Web3 APIs.
  • host: https://www.googleapis.com/* low Scoped to Google APIs; expected for Firebase/OAuth auth.
  • host: https://content.dropboxapi.com/* medium Dropbox API access; used for backup, but non-obvious for a wallet.
  • host: https://api.getwombat.io/* low Developer-owned API; scoped and expected.

Pillar Scores

Permissions3.30
Reputation4.50
Network2.50
Webstore1.00
Maintenance0.00
Privacy9.00
Code Quality0.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:17
Listing SHA 61e8c8e2723f…
Force block — not fired
Score recovered no
Elapsed 27.5s