Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Speed Bitcoin Lightning Wallet

miccfnlbijkmbckaagllchcfknjhgfnk
Risk Score
3.09
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Other
Installs 9,000
Rating 3.8
Last updated 2026-05-11 (1 months ago)
Manifest version MV3
CSP present ✅ yes
Developer itsupport@speed.app
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but scope_extension==false with data_collection+third_party_sharing true — full score 10 on privacy pillar.
  • Content script runs on <all_urls> giving broad DOM access on all pages including financial sites.
  • Dynamic script creation (script_src_dynamic) in content bundle; webpack nonce pattern but unverifiable at runtime.
  • new Function() constructor in content bundle; webpack globalThis shim pattern but elevates code-quality risk.
  • No developer display name on listing; developer identity relies solely on email domain speed.app.

Evidence

  • privacy_policy_scope_mismatch api Policy fetched (283 KB) but scope_extension=false, data_collection=true, third_party_sharing=true → privacy pillar 10.0.
  • content_scripts_all_urls manifest content_scripts_matches=['<all_urls>'] — injects into every page including other financial/crypto sites.
  • code_finding_script_src_dynamic crx Dynamic <script> element creation in content.bundle.js; webpack chunk-loading pattern.
  • code_finding_function_constructor crx new Function('return this') in content.bundle.js; standard webpack globalThis polyfill.
  • verified_publisher store Extension carries verified publisher badge; developer domain speed.app resolves.
  • react_16.13.1_bundled crx React 16.13.1 bundled; below 16.4 CVE threshold but no OSV CVEs reported in cve_findings_raw.
  • no_bad_hosts_or_affiliate api threat_intel: bad_host_hits=[], affiliate_hits=[], monetization_hits=[], js_external_hosts=[].
  • no_developer_name store developer_name is empty string; identity relies on email itsupport@speed.app only.

Permissions Breakdown

  • identity low OAuth identity; low risk without broad host scopes.
  • tabs medium Can read tab URLs and titles; moderate info-disclosure risk.
  • storage low Local extension storage; expected for wallet state persistence.
  • gcm low Push notifications via Google Cloud Messaging; limited risk.
  • content_scripts <all_urls> high Content script injected on all URLs; broad DOM read/write capability.
  • host_permissions: https://images.tryspeed.com/ low Narrow single-domain host permission for image fetching.

Pillar Scores

Permissions3.30
Reputation3.50
Network0.00
Webstore0.00
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:55
Listing SHA 4901c4066480…
Force block — not fired
Score recovered no
Elapsed 25.8s