111Proxy - Free Proxy Switcher & IP Changer
ecanngomflcfedphljhinajcgamkgjhn
Risk Score
6.24
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- proxy + webRequest + <all_urls>: can silently reroute and intercept all browser traffic
- Privacy policy is Google's own generic policy — no extension-specific data scope disclosed at all
- Developer is anonymous (no name, free-webmail Gmail) with no verifiable identity
- small_install_high_perm anomaly: only 219 users yet maximum network-intercept capability
- No CSP on MV3 extension with sensitive proxy/webRequest permissions
Evidence
- HIGH permissions cluster manifest proxy + webRequest + webRequestAuthProvider + privacy + <all_urls> — full traffic interception and rerouting capability.
- Privacy policy is generic Google account policy store scope_extension=false, data_collection=true, third_party_sharing=true → v3.5 rule D: +10.0 privacy.
- Anonymous developer store developer_name empty, developer_email linucat.com@gmail.com (free webmail, no verified business).
- No CSP manifest content_security_policy is null; MV3 has strict default but no explicit CSP increases risk.
- External host ipwho.is crx Extension contacts ipwho.is (IP geolocation service) — consistent with proxy function but unverified.
- install_perm_anomaly api small_install_high_perm=true, has_high_tier_permission=true, only 219 installs.
- No bad-host or affiliate hits api threat_intel shows no bad_host_hits, affiliate_hits, or monetization_hits — reduces some threat.
- No code findings / obfuscation crx obfuscation_score=0.0, code_findings_raw empty — no active exfil patterns detected.
Permissions Breakdown
- proxy high Can reroute all browser traffic through arbitrary servers — critical capability.
- webRequest high Intercept and observe all HTTP/S requests across every site.
- webRequestAuthProvider high Can inject authentication credentials into requests.
- privacy high Can alter browser privacy settings including WebRTC, referrer, etc.
- <all_urls> high Host permission covering every URL — full network visibility.
- storage low Local config persistence; low risk on its own.
- clipboardWrite medium Can overwrite clipboard content without user gesture.
Pillar Scores
Permissions9.00
Reputation8.00
Network4.50
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:29
Listing SHA
f9ad8a9a6225…
Force block
— not fired
Score recovered
no
Elapsed
23.5s