Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

111Proxy - Free Proxy Switcher & IP Changer

ecanngomflcfedphljhinajcgamkgjhn
Risk Score
6.24
Risk Level: High
Recommendation: 🚫 BLOCK
Category PrivacyTool
Installs 219
Rating
Last updated 2026-06-14
Manifest version MV3
CSP present ❌ no
Developer linucat.com@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy + webRequest + <all_urls>: can silently reroute and intercept all browser traffic
  • Privacy policy is Google's own generic policy — no extension-specific data scope disclosed at all
  • Developer is anonymous (no name, free-webmail Gmail) with no verifiable identity
  • small_install_high_perm anomaly: only 219 users yet maximum network-intercept capability
  • No CSP on MV3 extension with sensitive proxy/webRequest permissions

Evidence

  • HIGH permissions cluster manifest proxy + webRequest + webRequestAuthProvider + privacy + <all_urls> — full traffic interception and rerouting capability.
  • Privacy policy is generic Google account policy store scope_extension=false, data_collection=true, third_party_sharing=true → v3.5 rule D: +10.0 privacy.
  • Anonymous developer store developer_name empty, developer_email linucat.com@gmail.com (free webmail, no verified business).
  • No CSP manifest content_security_policy is null; MV3 has strict default but no explicit CSP increases risk.
  • External host ipwho.is crx Extension contacts ipwho.is (IP geolocation service) — consistent with proxy function but unverified.
  • install_perm_anomaly api small_install_high_perm=true, has_high_tier_permission=true, only 219 installs.
  • No bad-host or affiliate hits api threat_intel shows no bad_host_hits, affiliate_hits, or monetization_hits — reduces some threat.
  • No code findings / obfuscation crx obfuscation_score=0.0, code_findings_raw empty — no active exfil patterns detected.

Permissions Breakdown

  • proxy high Can reroute all browser traffic through arbitrary servers — critical capability.
  • webRequest high Intercept and observe all HTTP/S requests across every site.
  • webRequestAuthProvider high Can inject authentication credentials into requests.
  • privacy high Can alter browser privacy settings including WebRTC, referrer, etc.
  • <all_urls> high Host permission covering every URL — full network visibility.
  • storage low Local config persistence; low risk on its own.
  • clipboardWrite medium Can overwrite clipboard content without user gesture.

Pillar Scores

Permissions9.00
Reputation8.00
Network4.50
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:29
Listing SHA f9ad8a9a6225…
Force block — not fired
Score recovered no
Elapsed 23.5s