Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Altitude Wallet

ignmaajmjkdebcaekjkelgopdgjbnjhk
Risk Score
2.92
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Security
Installs 8
Rating 5.0
Last updated 2026-08-27 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@altitudedp.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection and third-party sharing but is not scoped to this extension — earns maximum privacy score.
  • Broad host access (<all_urls> + content scripts on all sites) with only 8 installs creates a disproportionate attack surface.
  • No developer name listed; anonymous publisher increases accountability risk.
  • 9 external JS hosts including Vercel blob storage — uncommon for a wallet; supply-chain risk if any host is compromised.
  • Small-install + high-permission anomaly flagged; tail-attack-surface risk for future compromise or silent sale.

Evidence

  • host_permissions_all_urls manifest <all_urls> host permission + content_scripts on <all_urls>: extension runs on every site user visits.
  • privacy_policy_generic api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true — not scoped to extension.
  • no_developer_name store developer_name field is empty; no 'Offered by' identity visible.
  • external_js_hosts crx 9 external hosts including vercel-storage blob CDN and localhost; supply-chain exposure.
  • install_perm_anomaly api Only 8 installs with high-tier host permission — small_install_high_perm=true.
  • no_csp manifest csp_present=false on MV3; default MV3 CSP applies but no explicit extension policy declared.
  • verified_publisher_false store Not a verified publisher, not featured by Google; no trust signals.
  • clean_code_scan crx code_findings_raw empty, obfuscation_score=0.0, no CVEs, no bad-host hits.

Permissions Breakdown

  • storage low Stores local wallet data; expected for a wallet extension.
  • sidePanel low Opens sidebar UI; low direct risk.
  • <all_urls> (host_permissions) high Grants content script access to every page; can read/modify all web content.
  • <all_urls> (content_scripts_matches) high Injects JS on every site; broad reach for a crypto wallet.

Pillar Scores

Permissions4.00
Reputation6.00
Network2.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 08:14
Listing SHA 81e545d2589e…
Force block — not fired
Score recovered no
Elapsed