| Contextual Risk Factors | Risk Factor | | The following context increases the overall risk:• 20% increase: Access to sensitive domains increases potential impact• 10% increase: Early script execution enables pre-emptive content manipulation• 25% increase: Unsafe code evaluation capabilities increase attack surface |
| Unsafe WebAssembly Execution | Risk Factor | | This extension's CSP allows "wasm-unsafe-eval". |
| storage | Permission | | This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads. |
| activeTab | Permission | | This permission grants temporary access to the current tab. Rated Medium because it can access current page content when invoked, though limited to user-initiated actions. |
| https://*.blonect.io/* | Host | | Host permission — access limited to this URL pattern. |
| https://api.blonect.net/* | Host | | Host permission — access limited to this URL pattern. |
| https://*.wer2chain.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://*.wer2scan.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://wer2view.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://eth.llamarpc.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://cloudflare-eth.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://rpc.ankr.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://polygon-rpc.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://arb1.arbitrum.io/* | Host | | Host permission — access limited to this URL pattern. |
| https://mainnet.base.org/* | Host | | Host permission — access limited to this URL pattern. |
| https://mainnet.optimism.io/* | Host | | Host permission — access limited to this URL pattern. |
| https://bsc-dataseed.binance.org/* | Host | | Host permission — access limited to this URL pattern. |
| https://bsc-dataseed1.defibit.io/* | Host | | Host permission — access limited to this URL pattern. |
| https://api.avax.network/* | Host | | Host permission — access limited to this URL pattern. |
| Access to Sensitive Domains | Risk Factor | | This extension requests access to sensitive domains: https://bsc-dataseed.binance.org/* |
| Early Content Script Execution | Risk Factor | | This extension runs content scripts at document_start. |
| notifications | Permission | | This permission displays system notifications. Rated Low because it can only show user-visible notifications without accessing system data. |
| alarms | Permission | | This permission schedules periodic tasks. Rated Low because it can only trigger events at specified times without access to sensitive data. |