HOT Wallet
mpeengabcnhhjjgleiodimegnkpcenbk
Risk Score
4.59
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Broad host permissions (all HTTP/HTTPS) + scripting allow JS injection into every page including crypto exchanges — high-value target for seed-phrase theft.
- Privacy policy fetched but scope_extension=false AND data_collection=true AND third_party_sharing=true — policy admits data sharing without scoping to this extension.
- No CSP on MV3 extension; innerHTML sink in bundled styled-components elevates DOM-XSS risk across all visited pages.
- No developer display name listed in store; reduces accountability for a financial/wallet extension handling private keys.
- 12 external JS hosts contacted including onramp.money fiat on-ramp; third-party data flow from a wallet extension warrants scrutiny.
Evidence
- broad_host_permissions manifest host_permissions http://*/* and https://*/* combined with scripting and content_scripts on all URLs.
- privacy_policy_scope_mismatch crx Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true — generic policy admitting 3rd-party sharing.
- no_csp manifest content_security_policy is null; no CSP protection for MV3 extension.
- dom_xss_sink crx innerHTML user-controlled sink in styled-components.browser.esm; no CSP mitigates risk.
- external_hosts_count crx 12 distinct external JS hosts including onramp.money, t.me, fonts.googleapis.com, api0.herewallet.app.
- no_developer_name store developer_name is empty string; reduced accountability for a financial wallet extension.
- install_count_reach store 100,000 installs; broad attack surface if extension is ever compromised or sold.
- cve_findings_raw_empty crx No CVEs detected in bundled libraries; CVE pillar score 0.0.
Permissions Breakdown
- storage low Standard wallet key/preference storage.
- unlimitedStorage low Extended local storage for blockchain data; expected for wallet.
- tabs medium Can read tab URLs and navigate; moderate surveillance surface.
- activeTab medium Access to active page on user gesture; limited scope.
- sidePanel low UI surface only; no data access by itself.
- contextMenus low Adds right-click menu items; low risk.
- scripting medium Can inject JS into pages; combined with broad host access this is significant.
- http://*/* high Broad host permission enabling content-script and scripting injection on all HTTP sites.
- https://*/* high Broad host permission on all HTTPS sites; covers banking, crypto exchanges, etc.
Pillar Scores
Permissions5.50
Reputation6.00
Network4.00
Webstore1.00
Maintenance1.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:57
Listing SHA
53899062ee06…
Force block
— not fired
Score recovered
no
Elapsed
26.6s