Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Stargazer Wallet

pgiaagfkgcbnmiiolekcfmljdagdhlcm
Risk Score
4.29
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Security
Installs 10,000
Rating 3.7
Last updated 2026-02-12 (4 months ago)
Manifest version MV3
CSP present ✅ yes
Developer developer@constellationnetwork.io
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but does NOT scope to this extension and admits third-party sharing — scores maximum 10.0.
  • Broad host permissions (http://*/*, https://*/*) with content_scripts on all URLs — wallet can read/modify every page.
  • function_constructor (new Function) + innerHTML DOM-XSS sink in options bundle — code execution surface.
  • No developer display name; unverified publisher with 3.7 rating raises accountability concerns.
  • 12 distinct external JS hosts including third-party (api.cypherock.com, CoinGecko) — large network attack surface.

Evidence

  • broad_host_permissions manifest host_permissions and content_scripts_matches both cover http://* and https://* — full web access.
  • privacy_policy_inadequate crx Policy fetched; scope_extension=false, data_collection=false, third_party_sharing=true — generic, unscoped.
  • function_constructor crx new Function() in js/options.bundle.js — dynamic code execution risk.
  • dom_sink_innerhtml crx innerHTML assigned from variable in js/options.bundle.js — DOM-XSS sink present.
  • no_developer_name store developer_name is empty; only email domain available (constellationnetwork.io).
  • external_hosts_count crx 12 external JS hosts: api.cypherock.com, CoinGecko (2), S3 buckets (3), DAG Explorer (2), Constellation API (3).
  • rating_concern store Rating 3.7 — below average for a crypto wallet; rating_count not disclosed.
  • cve_findings_empty crx No CVEs found in bundled libraries; cve_findings_raw is empty.

Permissions Breakdown

  • tabs medium Can read tab URLs and titles across all sites.
  • activeTab low Scoped to user-initiated interactions only.
  • storage low Local extension storage; wallet state expected.
  • unlimitedStorage low Expanded storage quota; normal for crypto wallet.
  • http://*/* high Broad host access to all HTTP sites via host_permissions.
  • https://*/* high Broad host access to all HTTPS sites via host_permissions.

Pillar Scores

Permissions5.50
Reputation5.50
Network3.50
Webstore1.00
Maintenance0.00
Privacy10.00
Code Quality4.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:04
Listing SHA db0c2841ef84…
Force block — not fired
Score recovered no
Elapsed 23.6s