Turbo VPN - Secure Free VPN Proxy
bnlofglpdlboacepdieejiecfbfpmhlb
Risk Score
4.08
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy hosted on CloudFront CDN, not dev domain; data_collection+third_party_sharing true, scope_extension false — admits data collection without scoping to this extension.
- Proxy + webRequest + *://*/* combination gives full traffic interception/redirection capability across all sites.
- Uninstall URL hijack detected — extension registers a third-party URL on removal.
- Developer name field is empty; only email identifier available; VPN with no named developer is a governance gap.
- Rating is 3.5 which is below average for an 800K-install VPN, suggesting user dissatisfaction.
Evidence
- privacy_policy_generic_scope api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → v3.5D applies: +10.0 privacy.
- proxy+webRequest+broad_host manifest proxy, webRequest, webRequestAuthProvider, *://*/* declared; full traffic interception capability. Justified-broad discount applied (VPN).
- uninstall_url_hijack crx uninstall_url_hijack=true; extension registers callback URL on removal — Webstore +3.0.
- verified_publisher_featured store verified_publisher=true, is_featured_by_google=true; discounts applied but capped due to monetization concern.
- developer_name_missing store developer_name is empty string; no named publisher identity despite 800K installs.
- no_cve_findings crx cve_findings_raw=[]; vue@3.4.38 bundled, no known CVEs. CVE pillar=0.0.
- code_findings_clean crx code_findings_raw=[]; obfuscation_score=0.0; no exfil/eval/redirect indicators.
- install_count_large store 800,000 installs; +1.0 Webstore (>100K). Rating 3.5 below average for scale.
Permissions Breakdown
- storage low Stores user preferences/settings; expected for VPN config.
- activeTab medium Access to currently active tab; limited scope but combined with proxy is notable.
- proxy high Full proxy control — can intercept and redirect all browser traffic.
- webRequest high Can observe all network requests; core to VPN function but high capability.
- webRequestAuthProvider high Can supply auth credentials for network requests; high sensitivity for a VPN.
- *://*/* high Broad host access across all URLs; expected for VPN but amplifies other HIGH permissions.
Pillar Scores
Permissions6.50
Reputation2.00
Network2.00
Webstore2.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:21
Listing SHA
32f7d49e6561…
Force block
— not fired
Score recovered
no
Elapsed
24.1s