Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Ctrl Wallet

hmeobnfnfcmdkdcmlblgagmfpfboieaf
Risk Score
3.63
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Security
Installs 200,000
Rating 4.7
Last updated 2026-06-08
Manifest version MV3
CSP present ✅ yes
Developer rnd@emurgo.io
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Broad host access (https://*/* + http://*/* + content_scripts <all_urls>) on a crypto wallet gives full page DOM access on every site, including exchanges and banking.
  • Privacy policy at xdefi.io does not scope to this extension but admits data collection and third-party sharing — high data governance risk.
  • 12 distinct external JS hosts including xdefi.services, apollo, etherscan, cloudflare-eth — broad network surface for a wallet extension.
  • DOM-XSS innerHTML sink in options.1744a0b2.js; CSP present but wasm-unsafe-eval in script-src; XSS could compromise wallet keys.
  • Developer name field empty; privacy policy domain (xdefi.io) differs from developer domain (emurgo.io), reducing accountability clarity.

Evidence

  • broad_host_permissions manifest host_permissions: https://*/* and http://*/* with content_scripts on <all_urls>; full cross-site DOM access.
  • privacy_policy_scope_mismatch store Policy at xdefi.io: fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 privacy pillar.
  • external_hosts_count crx 12 distinct external JS hosts: xdefi.services, etherscan.io, cloudflare-eth.com, apollo, github.com, feross.org, socket.io, etc.
  • dom_xss_sink crx options.1744a0b2.js: innerHTML assignment from variable; DOM-XSS risk in wallet options page.
  • verified_publisher store verified_publisher=true; discount applied but capped to -1.0 due to monetization_hits check (clean) — full -3.0 applied (no cap triggers).
  • developer_name_missing store developer_name is empty string; reduces accountability; +1.0 Reputation penalty applied.
  • no_cve_findings crx cve_findings_raw is empty; CVE pillar = 0.0.
  • recently_updated store months_since_update=0; Maintenance pillar = 0.0.

Permissions Breakdown

  • storage low Standard wallet key/state persistence; expected for crypto wallet.
  • scripting medium Programmatic script injection into pages; combined with broad host access elevates risk.
  • activeTab low Scoped to current tab on user action; lower risk than persistent host access.
  • tabs medium Can read tab URLs and metadata across all open tabs.
  • commands low Keyboard shortcut binding; minimal risk.
  • https://*/* high Broad host access across all HTTPS sites; crypto wallet can inject into banking/exchange pages.
  • http://*/* high Broad host access across all HTTP sites; same surface as HTTPS grant.
  • content_scripts <all_urls> high Content scripts injected on every URL; persistent access to page DOM including sensitive data.

Pillar Scores

Permissions4.50
Reputation3.00
Network3.50
Webstore2.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:40
Listing SHA 194703a2a826…
Force block — not fired
Score recovered no
Elapsed 27.6s