Portal DEX
ieldiilncjhfkalnemgjbffmpomcaigi
Risk Score
5.12
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic policy — not scoped to this extension, yet admits data collection and third-party sharing (+10.0 privacy).
- Broad host permissions (http://*/*, https://*/*, wss://*/*) plus scripting allow content injection on every site.
- 12 external JS hosts contacted including blockchain RPCs, Sentry telemetry, and several third-party infra domains — broad network surface.
- new Function() constructor in contentscript.js running in broad-host context is a code-execution risk.
- Not a verified publisher; privacy policy is a generic Google URL unrelated to this extension.
Evidence
- broad_host_permissions manifest host_permissions include http://*/*, https://*/*, wss://*/*giving access to all sites.
- generic_google_privacy_policy store privacy_policy_url points to Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- function_constructor_in_content_script crx new Function() constructor found in contentscript.js which runs on all pages.
- broad_csp_connect_src crx connect-src allows 30+ distinct origins including quiknode, alchemy, infura, sentry, IPFS, rafa.ai, and wildcard *.
- 12_external_js_hosts crx js_external_hosts: etherscan, solscan, llamarpc, publicnode, blockstream, solana RPC, portaldefi.zone, portaltobitcoin.zone, etc.
- unverified_publisher store verified_publisher=false, is_featured_by_google=false; dev domain portaldefi.com resolves but not verified.
- no_cve_findings crx cve_findings_raw empty; no known CVEs in bundled libraries despite lodash/react/viem present.
- recently_updated_mv3 manifest manifest_version=3, months_since_update=2; maintenance risk low.
CVE Exposures (8)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2026-2739 | bn.js@unknown | moderate | 4.12.3 | bn.js affected by an infinite loop |
| CVE-2021-23337 | lodash@unknown | high | 4.17.21 | Command Injection in lodash |
| CVE-2026-4800 | lodash@unknown | high | 4.17.21 | Command Injection in lodash |
| CVE-2018-16487 | lodash@unknown | high | 4.17.11 | Prototype Pollution in lodash |
| CVE-2025-13465 | lodash@unknown | moderate | 4.18.0 | lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and |
| CVE-2026-2950 | lodash@unknown | moderate | 4.18.0 | lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and |
| CVE-2018-3721 | lodash@unknown | moderate | 4.17.5 | Prototype Pollution in lodash |
| CVE-2019-10744 | lodash@unknown | critical | 4.17.12 | Prototype Pollution in lodash |
Permissions Breakdown
- activeTab low Accesses current tab on user action only.
- scripting medium Can inject scripts into pages; paired with broad host permissions.
- storage low Local extension data storage.
- tabs medium Can read tab URLs and metadata across all tabs.
- unlimitedStorage low No data-exfil risk on its own; allows large local data.
- sidePanel low UI surface only.
- notifications low Can push system notifications; low direct risk.
- http://*/* high Broad host access: content scripts run on all HTTP sites.
- https://*/* high Broad host access: content scripts run on all HTTPS sites.
- wss://*/* high Broad WebSocket access; can intercept WS traffic on any site.
Pillar Scores
Permissions6.50
Reputation5.00
Network5.50
Webstore1.00
Maintenance0.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00
Scoring History
| <fsssiedxg"sssiedx | 6.25 | High | review | 2026-08-15 |
| <fsssiedxg$"sssiedx | 6.14 | High | block | 2026-08-15 |
| fsssiedxw"sssiedx | 5.86 | Medium | block | 2026-08-15 |
| sssieddrubricxsx | 4.70 | Medium | block | 2026-08-15 |
| v3.6&n941234=v939860 | 6.27 | High | block | 2026-08-05 |
| v3.6'"()&%<zzz><ScRiPt >C2v0(9083)</ScRiPt> | 5.88 | Medium | review | 2026-07-29 |
| v3.6 | 5.12 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:42
Listing SHA
957e18fe2d19…
Force block
— not fired
Score recovered
no
Elapsed
25.1s