Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

TokenPocket - Web3 & Crypto Wallet

mfgccjchihfkkindfppnaooecgfneiii
Risk Score
4.51
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Security
Installs 90,000
Rating 3.6
Last updated 2026-06-15
Manifest version MV3
CSP present ✅ yes
Developer service@tokenpocket.pro
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection and third-party sharing but is NOT scoped to this extension — worst-case privacy posture.
  • scripting + <all_urls>: can inject JavaScript into any page including banking/crypto sites.
  • install_url_hijack and uninstall_url_hijack flags set — extension opens URLs on install/uninstall lifecycle events.
  • No developer display name; unverified publisher despite verified_publisher flag; rating 3.6 is below average.
  • Content scripts match http://*/* and https://*/* (all sites) plus specific hardware wallet popup pages — very broad injection surface.

Evidence

  • broad_host_scripting manifest host_permissions: <all_urls> + scripting permission + content_scripts on http://*/* and https://*.
  • privacy_policy_worst_case api fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 per v3.5 rule D.
  • install_uninstall_url_hijack crx install_url_hijack=true and uninstall_url_hijack=true; targets null (not resolvable but flags set).
  • verified_publisher store verified_publisher=true; months_since_update=0, no monetization hits — full -3.0 discount applies.
  • no_developer_name store developer_name is empty string; display identity gap increases accountability risk.
  • rating_below_average store Rating 3.6; rating_count unknown — cannot apply +1.0 rule without confirmed >=50 ratings.
  • content_scripts_hardware_wallet manifest Content scripts on trezor.io and keypal.pro popup pages — hardware wallet interaction surface.
  • cve_clean crx cve_findings_raw empty; react 17.0.2 bundled but no CVEs flagged; obfuscation_score=0.0.

Permissions Breakdown

  • storage low Stores wallet config locally; expected for crypto wallet.
  • unlimitedStorage low Large local storage for wallet data; expected.
  • notifications low Transaction/alert notifications; expected for wallet.
  • tabs medium Can read tab URLs and navigate; moderate risk.
  • offscreen low Offscreen document for background crypto operations.
  • activeTab medium Access to active tab on user action; scoped.
  • windows low Manage extension popup windows.
  • sidePanel low Side panel UI; low risk.
  • scripting high Can inject scripts into pages; high capability paired with <all_urls>.
  • <all_urls> high Broad host access across all sites; enables content injection everywhere.

Pillar Scores

Permissions6.50
Reputation3.50
Network2.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:54
Listing SHA be89d0166f4f…
Force block — not fired
Score recovered no
Elapsed 22.4s