Rainbow
Best for open-source verification
How it rates
- Source published in a public repository
- No dedicated security page identified at this check
Each indicator scores 2, 1 or 0. A pillar is the points earned over the points available; the overall score is the weighted sum. Every source below is public — check any of them yourself.
- MetSource code published in a public repository
Repository reachable at this check.
github.com/rainbow-me/rainbow - Not metSecurity documentation or disclosure page published
Not identified at this check.
- Not metUser documentation reachable without an account
Not identified at this check.
- MetPublisher identifiable from its own repository organisation
Repository published under Rainbow.
github.com/rainbow-me/rainbow - Met
- Met
- Met
- Not metDocumentation states how the product is funded or priced
Not identified at this check.
- Met
- Met
- Met
- Met
- Met
- Not metDocumentation site published
Not identified at this check.
- Not metSecurity posture stated publicly
No dedicated security page identified at this check.
- Met
- Met
- Not metSecurity or disclosure page published
Not identified at this check.
- Met
- Not metSupport or help resource published
Not identified at this check.
- Met
- Not metDocumentation reachable
Not identified.
- Met
- Not metSecurity page reachable
Not identified.
- Met
An open-source Ethereum wallet known for design quality and approachable onboarding, with a much thinner published documentation surface.
Our assessment
Rainbow is an open-source Ethereum wallet known for design quality — readable transaction history, clean NFT display, and an onboarding flow that does not assume prior knowledge. Its published documentation surface is much thinner than its product.
Design as an onboarding argument
Most people who abandon self-custody do so in the first hour, not the first year. Rainbow spends its effort on that hour: clear language, sensible defaults, and a portfolio view that makes sense to someone who has never seen a block explorer. That is a real contribution, even though our rubric has no indicator for it.
What is verifiable
Source code is published under the vendor organisation, and the publisher is identifiable from its own repository — so the code is auditable and the maker is known. Those are the two hardest things for a wallet to fake, and Rainbow has both.
Where nine indicators failed
We found no documentation site at a conventional address, no security or disclosure page, no user documentation reachable without an account, and no statement of how the product is funded or priced. For a free consumer wallet, how it makes money is not a trivial question — the usual answer is swap fees, and a user is entitled to see it written down.
Who it suits
Rainbow fits newcomers to Ethereum who value a wallet that explains itself, and who accept that its published documentation is limited. Users who want depth — approval management, simulation, multi-chain breadth — should look at Rabby, MetaMask or Trust Wallet.
How rivals compare
Frequently asked
Does this score mean Rainbow is safe?
No. It measures what a user can verify before installing: published source, documented security posture, open documentation and an identifiable publisher. Runtime key handling is not tested by us.
Why does open source matter for a wallet?
It is the one substantive property an outsider can check without reverse-engineering the app. Everything else requires trusting the publisher or a third-party audit.
What would raise this score?
Publishing source, a dedicated security page, open documentation and terms at stable public addresses — all checkable by anyone.