Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Magic Eden Wallet

mkpegjkblkkefacfnmkajcjmabijhclg
Risk Score
2.92
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Security
Installs 200,000
Rating 4.2
Last updated 2026-04-02 (2 months ago)
Manifest version MV3
CSP present ✅ yes
Developer Emmy.appstore@magiceden.io
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but does not scope data collection to this extension; third-party sharing silence noted.
  • Content script injected on all HTTPS pages gives broad DOM access across every site visited.
  • Developer name field is empty; identity relies solely on email domain magiceden.io.
  • CSP connect-src allows 'https: wss: data: blob:' broadly, permitting outbound connections to any HTTPS host.
  • No verified-publisher badge; cannot confirm store-listing ownership by Magic Eden Inc.

Evidence

  • content_scripts_broad manifest Content script matches https://*/*; injects wallet provider into every HTTPS page.
  • csp_connect_src_broad manifest connect-src 'https: wss: data: blob:' allows outbound to any HTTPS/WSS endpoint.
  • privacy_policy_no_extension_scope api Policy fetched (107 KB) but scope_extension=false and data_collection=false; generic site policy.
  • no_developer_name store developer_name is empty string; identity unverifiable beyond email domain magiceden.io.
  • js_external_hosts crx 3 external hosts referenced: cloudfront.net CDN, eips.ethereum.org, github.com.
  • no_cve_findings crx cve_findings_raw empty; no known-vulnerable bundled libraries detected.
  • no_bad_hosts api threat_intel bad_host_hits, affiliate_hits, and monetization_hits all empty.
  • recently_updated store Last updated April 2, 2026 (2 months ago); actively maintained.

Permissions Breakdown

  • alarms low Background scheduling; low risk on its own.
  • content_scripts: https://*/* medium Injects into all HTTPS pages; required for wallet provider injection but broadens attack surface.
  • content_scripts: localhost/127.0.0.1/[::1] low Local dev-node access; typical for Web3 wallet dApp interaction on localhost.
  • storage low Standard local data persistence; expected for a wallet extension.
  • unlimitedStorage low Allows large local storage; appropriate for a crypto wallet with cached chain data.

Pillar Scores

Permissions2.30
Reputation5.50
Network3.50
Webstore1.00
Maintenance0.00
Privacy9.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:56
Listing SHA e1c0171a5559…
Force block — not fired
Score recovered no
Elapsed 20.0s