Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Free VPN Proxy - 1VPN

akcocjjpkmlniicdeemdceeajlmoabhg
Risk Score
5.87
Risk Level: Medium
Recommendation: 🚫 BLOCK FORCE-BLOCK
Category VPN
Installs 2,000,000
Rating 4.7
Last updated 2026-07-19 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer contact@1vpn.org
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • FORCE BLOCK: management + broad host access — extension can disable security tools AND has full traffic-routing capability.
  • proxy + <all_urls> + webRequest: full traffic interception capability over all browsing with no CSP guard.
  • management permission allows disabling other security/privacy extensions.
  • Privacy policy: fetched, not scoped to extension, admits 3rd-party sharing — scores max privacy penalty.
  • install_url_hijack and uninstall_url_hijack both true; monetization/redirect risk at install and uninstall.

Evidence

  • proxy+webRequest+<all_urls> manifest Triple HIGH permissions: proxy, webRequest, <all_urls> — complete traffic interception surface.
  • management permission manifest management declared; can enumerate and disable other installed extensions.
  • install/uninstall URL hijack crx install_url_hijack=true, uninstall_url_hijack=true; target URLs null but hooks present.
  • privacy policy inadequate store Policy fetched (1586 chars), scope_extension=false, data_collection=false, third_party_sharing=true. Generic, admits 3P sharing.
  • no CSP crx content_security_policy is null; no CSP on MV3 extension with DOM-XSS sinks in code.
  • dom_sink_innerhtml_userctrl x2 crx innerHTML from variable in install.bundle.js and popup.bundle.js; no CSP mitigates DOM-XSS risk.
  • developer identity weak store developer_name empty, domain looks_throwaway per threat_intel, despite verified_publisher=true.
  • 2M installs + featured store 2,000,000 installs and is_featured_by_google=true; blast radius is very large.

Permissions Breakdown

  • proxy high Can route all browser traffic through attacker-controlled servers; core VPN function but extremely powerful.
  • webRequest high Intercept, inspect, and block any HTTP request across all sites.
  • privacy high Modify browser privacy settings (proxy, WebRTC, etc.).
  • management high Can enumerate, enable, or disable other installed extensions.
  • <all_urls> high Host permission for all URLs — enables content injection and full request interception.
  • scripting medium Programmatic script injection into any tab; combined with <all_urls> is broad.
  • webNavigation medium Monitor all navigation events across all tabs.
  • webRequestAuthProvider medium Supply HTTP authentication credentials; potential for credential interception.
  • activeTab low Limited to currently active tab on user gesture; low standalone risk.
  • storage low Local extension storage; low risk in isolation.
  • alarms low Scheduling background tasks; low risk.

Pillar Scores

Permissions7.50
Reputation3.50
Network2.00
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Scoring History

<fsssiedxg"sssiedx 5.12 Medium block 2026-08-15
<fsssiedxg 6.32 High block 2026-08-15
<fsssiedxg$"sssiedx 6.09 High block 2026-08-15
&#x22;fsssiedxw xx psssiedx 6.32 High block 2026-08-15
&#x22;fsssiedxw'sssiedx 6.37 High block 2026-08-15
&#x22;fsssiedxwfdsaxax><!--></ScRiPt>asddsssiedx 6.45 High block 2026-08-15
6.12 High block 2026-08-15
<fsssiedxwfdsaxax><!--></ScRiPt>asddsssiedx 6.27 High block 2026-08-15
<fsssiedxw$"sssiedx 6.37 High block 2026-08-15
<fsssiedx{fdsaxax><!--></ScRiPt>asddsssiedx 6.73 High block 2026-08-15
<fsssiedx{'sssiedx 6.56 High block 2026-08-15
fsssiedx<sssiedx 6.08 High block 2026-08-15
<fsssiedxa&#x27;sssiedx 6.59 High block 2026-08-04
<fsssiedxa$"sssiedx 5.03 Medium block 2026-08-04
<fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 6.84 High block 2026-08-04
<fsssiedxa xx psssiedx 6.49 High block 2026-08-04
<fsssiedxa&#x22;sssiedx 6.51 High block 2026-08-04
fsssiedxa<sssiedx 6.54 High block 2026-08-04
sssieddrubricxsx 6.87 High block 2026-08-04
v3.6 5.87 Medium block 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:17
Listing SHA 73ec167ef696…
Force block 🚫 fired
Score recovered no
Elapsed 28.9s