Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Portal DEX

ieldiilncjhfkalnemgjbffmpomcaigi
Risk Score
5.12
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 70,000
Rating 4.6
Last updated 2026-04-21 (4 months ago)
Manifest version MV3
CSP present ✅ yes
Developer support@portaldefi.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy — not scoped to this extension, yet admits data collection and third-party sharing (+10.0 privacy).
  • Broad host permissions (http://*/*, https://*/*, wss://*/*) plus scripting allow content injection on every site.
  • 12 external JS hosts contacted including blockchain RPCs, Sentry telemetry, and several third-party infra domains — broad network surface.
  • new Function() constructor in contentscript.js running in broad-host context is a code-execution risk.
  • Not a verified publisher; privacy policy is a generic Google URL unrelated to this extension.

Evidence

  • broad_host_permissions manifest host_permissions include http://*/*, https://*/*, wss://*/*giving access to all sites.
  • generic_google_privacy_policy store privacy_policy_url points to Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • function_constructor_in_content_script crx new Function() constructor found in contentscript.js which runs on all pages.
  • broad_csp_connect_src crx connect-src allows 30+ distinct origins including quiknode, alchemy, infura, sentry, IPFS, rafa.ai, and wildcard *.
  • 12_external_js_hosts crx js_external_hosts: etherscan, solscan, llamarpc, publicnode, blockstream, solana RPC, portaldefi.zone, portaltobitcoin.zone, etc.
  • unverified_publisher store verified_publisher=false, is_featured_by_google=false; dev domain portaldefi.com resolves but not verified.
  • no_cve_findings crx cve_findings_raw empty; no known CVEs in bundled libraries despite lodash/react/viem present.
  • recently_updated_mv3 manifest manifest_version=3, months_since_update=2; maintenance risk low.

CVE Exposures (8)

CVELibrarySeverity Fixed inSummary
CVE-2026-2739 bn.js@unknown moderate 4.12.3 bn.js affected by an infinite loop
CVE-2021-23337 lodash@unknown high 4.17.21 Command Injection in lodash
CVE-2026-4800 lodash@unknown high 4.17.21 Command Injection in lodash
CVE-2018-16487 lodash@unknown high 4.17.11 Prototype Pollution in lodash
CVE-2025-13465 lodash@unknown moderate 4.18.0 lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and
CVE-2026-2950 lodash@unknown moderate 4.18.0 lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and
CVE-2018-3721 lodash@unknown moderate 4.17.5 Prototype Pollution in lodash
CVE-2019-10744 lodash@unknown critical 4.17.12 Prototype Pollution in lodash

Permissions Breakdown

  • activeTab low Accesses current tab on user action only.
  • scripting medium Can inject scripts into pages; paired with broad host permissions.
  • storage low Local extension data storage.
  • tabs medium Can read tab URLs and metadata across all tabs.
  • unlimitedStorage low No data-exfil risk on its own; allows large local data.
  • sidePanel low UI surface only.
  • notifications low Can push system notifications; low direct risk.
  • http://*/* high Broad host access: content scripts run on all HTTP sites.
  • https://*/* high Broad host access: content scripts run on all HTTPS sites.
  • wss://*/* high Broad WebSocket access; can intercept WS traffic on any site.

Pillar Scores

Permissions6.50
Reputation5.00
Network5.50
Webstore1.00
Maintenance0.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Scoring History

<fsssiedxg"sssiedx 6.25 High review 2026-08-15
<fsssiedxg$"sssiedx 6.14 High block 2026-08-15
fsssiedxw"sssiedx 5.86 Medium block 2026-08-15
sssieddrubricxsx 4.70 Medium block 2026-08-15
v3.6&n941234=v939860 6.27 High block 2026-08-05
v3.6'"()&%<zzz><ScRiPt >C2v0(9083)</ScRiPt> 5.88 Medium review 2026-07-29
v3.6 5.12 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:42
Listing SHA 957e18fe2d19…
Force block — not fired
Score recovered no
Elapsed 25.1s