Speed Bitcoin Lightning Wallet
miccfnlbijkmbckaagllchcfknjhgfnk
Risk Score
3.09
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy fetched but scope_extension==false with data_collection+third_party_sharing true — full score 10 on privacy pillar.
- Content script runs on <all_urls> giving broad DOM access on all pages including financial sites.
- Dynamic script creation (script_src_dynamic) in content bundle; webpack nonce pattern but unverifiable at runtime.
- new Function() constructor in content bundle; webpack globalThis shim pattern but elevates code-quality risk.
- No developer display name on listing; developer identity relies solely on email domain speed.app.
Evidence
- privacy_policy_scope_mismatch api Policy fetched (283 KB) but scope_extension=false, data_collection=true, third_party_sharing=true → privacy pillar 10.0.
- content_scripts_all_urls manifest content_scripts_matches=['<all_urls>'] — injects into every page including other financial/crypto sites.
- code_finding_script_src_dynamic crx Dynamic <script> element creation in content.bundle.js; webpack chunk-loading pattern.
- code_finding_function_constructor crx new Function('return this') in content.bundle.js; standard webpack globalThis polyfill.
- verified_publisher store Extension carries verified publisher badge; developer domain speed.app resolves.
- react_16.13.1_bundled crx React 16.13.1 bundled; below 16.4 CVE threshold but no OSV CVEs reported in cve_findings_raw.
- no_bad_hosts_or_affiliate api threat_intel: bad_host_hits=[], affiliate_hits=[], monetization_hits=[], js_external_hosts=[].
- no_developer_name store developer_name is empty string; identity relies on email itsupport@speed.app only.
Permissions Breakdown
- identity low OAuth identity; low risk without broad host scopes.
- tabs medium Can read tab URLs and titles; moderate info-disclosure risk.
- storage low Local extension storage; expected for wallet state persistence.
- gcm low Push notifications via Google Cloud Messaging; limited risk.
- content_scripts <all_urls> high Content script injected on all URLs; broad DOM read/write capability.
- host_permissions: https://images.tryspeed.com/ low Narrow single-domain host permission for image fetching.
Pillar Scores
Permissions3.30
Reputation3.50
Network0.00
Webstore0.00
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:55
Listing SHA
4901c4066480…
Force block
— not fired
Score recovered
no
Elapsed
25.8s