TokenPocket - Web3 & Crypto Wallet
mfgccjchihfkkindfppnaooecgfneiii
Risk Score
4.51
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy admits data collection and third-party sharing but is NOT scoped to this extension — worst-case privacy posture.
- scripting + <all_urls>: can inject JavaScript into any page including banking/crypto sites.
- install_url_hijack and uninstall_url_hijack flags set — extension opens URLs on install/uninstall lifecycle events.
- No developer display name; unverified publisher despite verified_publisher flag; rating 3.6 is below average.
- Content scripts match http://*/* and https://*/* (all sites) plus specific hardware wallet popup pages — very broad injection surface.
Evidence
- broad_host_scripting manifest host_permissions: <all_urls> + scripting permission + content_scripts on http://*/* and https://*.
- privacy_policy_worst_case api fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 per v3.5 rule D.
- install_uninstall_url_hijack crx install_url_hijack=true and uninstall_url_hijack=true; targets null (not resolvable but flags set).
- verified_publisher store verified_publisher=true; months_since_update=0, no monetization hits — full -3.0 discount applies.
- no_developer_name store developer_name is empty string; display identity gap increases accountability risk.
- rating_below_average store Rating 3.6; rating_count unknown — cannot apply +1.0 rule without confirmed >=50 ratings.
- content_scripts_hardware_wallet manifest Content scripts on trezor.io and keypal.pro popup pages — hardware wallet interaction surface.
- cve_clean crx cve_findings_raw empty; react 17.0.2 bundled but no CVEs flagged; obfuscation_score=0.0.
Permissions Breakdown
- storage low Stores wallet config locally; expected for crypto wallet.
- unlimitedStorage low Large local storage for wallet data; expected.
- notifications low Transaction/alert notifications; expected for wallet.
- tabs medium Can read tab URLs and navigate; moderate risk.
- offscreen low Offscreen document for background crypto operations.
- activeTab medium Access to active tab on user action; scoped.
- windows low Manage extension popup windows.
- sidePanel low Side panel UI; low risk.
- scripting high Can inject scripts into pages; high capability paired with <all_urls>.
- <all_urls> high Broad host access across all sites; enables content injection everywhere.
Pillar Scores
Permissions6.50
Reputation3.50
Network2.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:54
Listing SHA
be89d0166f4f…
Force block
— not fired
Score recovered
no
Elapsed
22.4s