Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Turbo VPN - Secure Free VPN Proxy

bnlofglpdlboacepdieejiecfbfpmhlb
Risk Score
4.08
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VPN
Installs 800,000
Rating 3.5
Last updated 2025-07-12 (11 months ago)
Manifest version MV3
CSP present ✅ yes
Developer turbovpn-support@inconnecting.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy hosted on CloudFront CDN, not dev domain; data_collection+third_party_sharing true, scope_extension false — admits data collection without scoping to this extension.
  • Proxy + webRequest + *://*/* combination gives full traffic interception/redirection capability across all sites.
  • Uninstall URL hijack detected — extension registers a third-party URL on removal.
  • Developer name field is empty; only email identifier available; VPN with no named developer is a governance gap.
  • Rating is 3.5 which is below average for an 800K-install VPN, suggesting user dissatisfaction.

Evidence

  • privacy_policy_generic_scope api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → v3.5D applies: +10.0 privacy.
  • proxy+webRequest+broad_host manifest proxy, webRequest, webRequestAuthProvider, *://*/* declared; full traffic interception capability. Justified-broad discount applied (VPN).
  • uninstall_url_hijack crx uninstall_url_hijack=true; extension registers callback URL on removal — Webstore +3.0.
  • verified_publisher_featured store verified_publisher=true, is_featured_by_google=true; discounts applied but capped due to monetization concern.
  • developer_name_missing store developer_name is empty string; no named publisher identity despite 800K installs.
  • no_cve_findings crx cve_findings_raw=[]; vue@3.4.38 bundled, no known CVEs. CVE pillar=0.0.
  • code_findings_clean crx code_findings_raw=[]; obfuscation_score=0.0; no exfil/eval/redirect indicators.
  • install_count_large store 800,000 installs; +1.0 Webstore (>100K). Rating 3.5 below average for scale.

Permissions Breakdown

  • storage low Stores user preferences/settings; expected for VPN config.
  • activeTab medium Access to currently active tab; limited scope but combined with proxy is notable.
  • proxy high Full proxy control — can intercept and redirect all browser traffic.
  • webRequest high Can observe all network requests; core to VPN function but high capability.
  • webRequestAuthProvider high Can supply auth credentials for network requests; high sensitivity for a VPN.
  • *://*/* high Broad host access across all URLs; expected for VPN but amplifies other HIGH permissions.

Pillar Scores

Permissions6.50
Reputation2.00
Network2.00
Webstore2.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:21
Listing SHA 32f7d49e6561…
Force block — not fired
Score recovered no
Elapsed 24.1s