Авокадо ВПН — ежедневный VPN
cepookalkohkjhbamenfbagblnmfcfmn
Risk Score
4.36
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- proxy permission enables full MITM on all browser traffic via unvetted vpnfasters.space and app.myxavpn.pro endpoints
- install_url_hijack opens vpnfasters.space on install — third-party redirect from anonymous dev
- Privacy policy is Google's own generic policy; does not scope to this extension at all (D clause: +10.0)
- Free-webmail Gmail dev, no developer name, no verified publisher — anonymous operator
- Small-install + high-perm anomaly: only 10 users, proxy permission — classic tail-attack surface
Evidence
- proxy_permission manifest proxy declared — routes all traffic; combined with external hosts app.myxavpn.pro and vpnfasters.space.
- install_url_hijack store install_url_target=https://vpnfasters.space/ opens on install; third-party domain not controlled by dev.
- generic_google_privacy_policy store Privacy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0.
- anonymous_developer store developer_name empty, free Gmail address kameqoko032@gmail.com, no verified publisher badge.
- free_webmail_no_dev_name store Gmail dev + no name → Reputation floor applies; +1.5 free-webmail, +1.0 no dev name.
- js_external_hosts crx app.myxavpn.pro (NL), vpnfasters.space, t.me — 3 distinct registrable domains, geo NL+RU.
- install_perm_anomaly api small_install_high_perm=true: 10 installs with proxy permission — tail-attack surface.
- no_csp manifest csp_present=false on MV3; v2 fix (b) not triggered on MV3 but noted for network context.
Permissions Breakdown
- proxy high Routes all browser traffic through attacker-controlled server; full MITM capability.
Pillar Scores
Permissions7.00
Reputation8.00
Network4.50
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 13:29
Listing SHA
67ee59a00042…
Force block
— not fired
Score recovered
no
Elapsed
—