After doing some research lately, there is a way to be sure that a wallet is 99% legit, here are the points to check:
- there has to be no out transaction from the address that is in the wallet
- the transaction have to be 100% the same in the wallet as on the blockchain
- and the most important, after command "getwalletinfo" for a specific address in the wallet, the pubkey has to mach the address in the wallet, as the address has no out going transaction , the pubkey is not published in the blockchain, but the command will resolute a matching pubkey
An example is the 4000-BTC wallet