WebGuard
bngahmjkkbiebggdghdlbjaedhmcblpm
Risk Score
5.79
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- proxy permission routes all browser traffic through spidervpn.online — an unknown Russian-hosted endpoint with no verified publisher identity.
- Privacy policy is Google's generic policy; does not scope to this extension, yet admits data collection and third-party sharing — scores maximum privacy risk.
- Developer is anonymous (no name, free-webmail gmail, no business domain), elevating supply-chain and impersonation risk.
- Extremely low install count (8) combined with HIGH-tier proxy permission is a tail-attack-surface anomaly.
- External JS loaded from spidervpn.online (RU-hosted, single-country geo) with no CSP — unverifiable remote code at runtime.
Evidence
- proxy_permission manifest proxy declared — full browser traffic interception/redirection possible via spidervpn.online.
- external_js_host crx js_external_hosts: ['spidervpn.online'] — Russia-hosted, no CSP to constrain execution.
- no_csp manifest content_security_policy is null/csp_present=false; no runtime script restriction for MV3 extension.
- generic_privacy_policy store Policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- anonymous_developer store developer_name empty, free-webmail gmail, no business website — unverifiable identity.
- small_install_high_perm api install_perm_anomaly: 8 installs + proxy (HIGH-tier) — tail-attack-surface flag triggered.
- description_in_russian store manifest_description is Cyrillic ('Your network under protection'); geo/hosting also RU.
- no_verified_publisher store verified_publisher=false, is_featured_by_google=false — no accountability signals present.
Permissions Breakdown
- proxy high Full proxy control allows rerouting all browser traffic through attacker-controlled infrastructure.
- storage low Local key-value storage; low standalone risk.
Pillar Scores
Permissions7.00
Reputation8.50
Network4.00
Webstore4.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 15:48
Listing SHA
9cbb9532e32f…
Force block
— not fired
Score recovered
no
Elapsed
—