Wombat - Gaming Wallet for Ethereum & EOS
amkmjjmmflddogmhpjloimipbofnfjih
Risk Score
2.96
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Content script injected on <all_urls> gives wallet broad page-level read access across every site visited.
- Privacy policy fetched but does not scope to this extension or disclose data collection — privacy gap.
- Dropbox API host permission non-obvious for a wallet; backup scope not clearly documented.
- innerHTML DOM-XSS sink in options.bundle.js; low severity given CSP but worth hardening.
- Geo-diverse JS hosts (DE/IN/SG/US, 4 countries) raises supply-chain surface area slightly.
Evidence
- content_scripts_matches <all_urls> manifest Extension injects into every page; broad reach expected for Web3 wallet but elevates permissions risk.
- privacy_policy_scope_extension=false, data_collection=false crx Policy fetched but does not reference this extension or describe its data handling → +9.0 privacy.
- dom_sink_innerhtml_userctrl crx options.bundle.js uses innerHTML from variable; CSP present limits exploitability.
- host_geo_diversity country_count=4 crx JS external hosts span DE, IN, SG, US — 4 countries triggers +1.5 network geo penalty.
- no bad_host / affiliate / monetization hits api threat_intel all clear; developer domain resolves, not throwaway, no siblings.
- cve_findings_raw empty crx No known-CVE libraries detected; CVE pillar = 0.0.
- months_since_update=2 store Updated April 2026; maintenance risk = 0.
- unverified_publisher + no featured badge store No verified publisher or featured badge; reputation starts at 5.0 with no positive offsets.
Permissions Breakdown
- tabs medium Can read tab URLs and titles; medium risk for a wallet extension.
- storage low Local data persistence; standard for wallet state.
- clipboardWrite medium Can write to clipboard; acceptable for copy-address wallet UX.
- notifications low Push notifications; low risk, typical for tx alerts.
- identity low OAuth identity API without scopes; limited exposure.
- offscreen low Offscreen document for background tasks; no elevated capability.
- content_scripts <all_urls> high Injects into every page; broad reach for a crypto wallet injecting Web3 APIs.
- host: https://www.googleapis.com/* low Scoped to Google APIs; expected for Firebase/OAuth auth.
- host: https://content.dropboxapi.com/* medium Dropbox API access; used for backup, but non-obvious for a wallet.
- host: https://api.getwombat.io/* low Developer-owned API; scoped and expected.
Pillar Scores
Permissions3.30
Reputation4.50
Network2.50
Webstore1.00
Maintenance0.00
Privacy9.00
Code Quality0.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:17
Listing SHA
61e8c8e2723f…
Force block
— not fired
Score recovered
no
Elapsed
27.5s