Ctrl Wallet
hmeobnfnfcmdkdcmlblgagmfpfboieaf
Risk Score
3.63
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Broad host access (https://*/* + http://*/* + content_scripts <all_urls>) on a crypto wallet gives full page DOM access on every site, including exchanges and banking.
- Privacy policy at xdefi.io does not scope to this extension but admits data collection and third-party sharing — high data governance risk.
- 12 distinct external JS hosts including xdefi.services, apollo, etherscan, cloudflare-eth — broad network surface for a wallet extension.
- DOM-XSS innerHTML sink in options.1744a0b2.js; CSP present but wasm-unsafe-eval in script-src; XSS could compromise wallet keys.
- Developer name field empty; privacy policy domain (xdefi.io) differs from developer domain (emurgo.io), reducing accountability clarity.
Evidence
- broad_host_permissions manifest host_permissions: https://*/* and http://*/* with content_scripts on <all_urls>; full cross-site DOM access.
- privacy_policy_scope_mismatch store Policy at xdefi.io: fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 privacy pillar.
- external_hosts_count crx 12 distinct external JS hosts: xdefi.services, etherscan.io, cloudflare-eth.com, apollo, github.com, feross.org, socket.io, etc.
- dom_xss_sink crx options.1744a0b2.js: innerHTML assignment from variable; DOM-XSS risk in wallet options page.
- verified_publisher store verified_publisher=true; discount applied but capped to -1.0 due to monetization_hits check (clean) — full -3.0 applied (no cap triggers).
- developer_name_missing store developer_name is empty string; reduces accountability; +1.0 Reputation penalty applied.
- no_cve_findings crx cve_findings_raw is empty; CVE pillar = 0.0.
- recently_updated store months_since_update=0; Maintenance pillar = 0.0.
Permissions Breakdown
- storage low Standard wallet key/state persistence; expected for crypto wallet.
- scripting medium Programmatic script injection into pages; combined with broad host access elevates risk.
- activeTab low Scoped to current tab on user action; lower risk than persistent host access.
- tabs medium Can read tab URLs and metadata across all open tabs.
- commands low Keyboard shortcut binding; minimal risk.
- https://*/* high Broad host access across all HTTPS sites; crypto wallet can inject into banking/exchange pages.
- http://*/* high Broad host access across all HTTP sites; same surface as HTTPS grant.
- content_scripts <all_urls> high Content scripts injected on every URL; persistent access to page DOM including sensitive data.
Pillar Scores
Permissions4.50
Reputation3.00
Network3.50
Webstore2.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:40
Listing SHA
194703a2a826…
Force block
— not fired
Score recovered
no
Elapsed
27.6s