Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Аво ВПН

balkhnoegkmheodonbkhkaegibmamapp
Risk Score
4.00
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VPN
Installs 1,000
Rating 4.9
Last updated 2026-02-26 (7 months ago)
Manifest version MV3
CSP present ❌ no
Developer ezagirace763@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy URL returns fetch error — cannot verify data handling; treated as no policy (pillar score 10).
  • proxy permission routes all browser traffic; free-webmail developer with no verified identity raises compromise risk.
  • Developer email is free Gmail with no name or business identity — unaccountable if extension is sold or misused.
  • No developer name listed; free-webmail + missing identity floor keeps reputation pillar elevated.
  • Extension contacts myxavpn.com (JS external host) but site/policy unreachable — unknown backend operator.

Evidence

  • privacy_policy_fetch_failed api Privacy policy at myxavpn.com/privacy/ returned HTTPError; classified as fetched=false → pillar=10.
  • proxy_permission manifest proxy declared — routes all browser traffic; high-impact, matches VPN category so no mismatch penalty.
  • free_webmail_developer store Developer email ezagirace763@gmail.com, no developer name, no verified publisher.
  • js_external_host crx myxavpn.com is only external JS host; site unreachable so backend operator unverifiable.
  • no_code_findings crx code_findings_raw empty, obfuscation_score=0.0 — no malicious code signals detected.
  • no_cve_findings api cve_findings_raw empty; no known-vulnerable libraries bundled.
  • maintenance_3_6_months store months_since_update=7 → 6-12 month band → +3.5 maintenance score.
  • no_sibling_extensions api operator_cluster sibling_count=0; no cluster risk.

Permissions Breakdown

  • proxy high Can redirect all browser traffic through arbitrary proxy; core VPN function but high-impact capability.
  • storage low Stores extension settings locally; low inherent risk.

Pillar Scores

Permissions4.50
Reputation6.50
Network0.00
Webstore0.00
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 13:34
Listing SHA 50d5e1ebace7…
Force block — not fired
Score recovered no
Elapsed