Magic Eden Wallet
mkpegjkblkkefacfnmkajcjmabijhclg
Risk Score
2.92
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy fetched but does not scope data collection to this extension; third-party sharing silence noted.
- Content script injected on all HTTPS pages gives broad DOM access across every site visited.
- Developer name field is empty; identity relies solely on email domain magiceden.io.
- CSP connect-src allows 'https: wss: data: blob:' broadly, permitting outbound connections to any HTTPS host.
- No verified-publisher badge; cannot confirm store-listing ownership by Magic Eden Inc.
Evidence
- content_scripts_broad manifest Content script matches https://*/*; injects wallet provider into every HTTPS page.
- csp_connect_src_broad manifest connect-src 'https: wss: data: blob:' allows outbound to any HTTPS/WSS endpoint.
- privacy_policy_no_extension_scope api Policy fetched (107 KB) but scope_extension=false and data_collection=false; generic site policy.
- no_developer_name store developer_name is empty string; identity unverifiable beyond email domain magiceden.io.
- js_external_hosts crx 3 external hosts referenced: cloudfront.net CDN, eips.ethereum.org, github.com.
- no_cve_findings crx cve_findings_raw empty; no known-vulnerable bundled libraries detected.
- no_bad_hosts api threat_intel bad_host_hits, affiliate_hits, and monetization_hits all empty.
- recently_updated store Last updated April 2, 2026 (2 months ago); actively maintained.
Permissions Breakdown
- alarms low Background scheduling; low risk on its own.
- content_scripts: https://*/* medium Injects into all HTTPS pages; required for wallet provider injection but broadens attack surface.
- content_scripts: localhost/127.0.0.1/[::1] low Local dev-node access; typical for Web3 wallet dApp interaction on localhost.
- storage low Standard local data persistence; expected for a wallet extension.
- unlimitedStorage low Allows large local storage; appropriate for a crypto wallet with cached chain data.
Pillar Scores
Permissions2.30
Reputation5.50
Network3.50
Webstore1.00
Maintenance0.00
Privacy9.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:56
Listing SHA
e1c0171a5559…
Force block
— not fired
Score recovered
no
Elapsed
20.0s