VPN Simple
elflhijmcekbfdjkabgphiepeclgmjgl
Risk Score
4.50
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- proxy permission routes ALL browser traffic through stealthpath.space — unknown, unvetted operator with only 10 installs.
- Install-URL hijack opens stealthpath.space on install; classic phone-home / affiliate redirect pattern.
- Privacy policy is Google's own policy — completely unscoped to this extension; admits data collection and 3rd-party sharing.
- Free-webmail developer (silviaferr79@gmail.com), no developer name, no verified publisher — zero accountability.
- JS contacts app.myxavpn.pro and t.me in addition to proxy infrastructure — undisclosed external endpoints.
Evidence
- proxy_permission manifest proxy declared — can redirect all browser HTTP/HTTPS traffic to stealthpath.space or any host.
- install_url_hijack crx install_url_hijack=true; onInstalled opens https://stealthpath.space/ — undisclosed third-party redirect.
- generic_privacy_policy store Policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- free_webmail_no_dev_name store Developer is silviaferr79@gmail.com with empty developer_name; no business identity verifiable.
- undisclosed_external_hosts crx JS contacts app.myxavpn.pro and t.me — neither declared in host_permissions nor explained in description.
- geo_diversity api JS hosts span CA, NL, RU, US (4 countries); country_count>=4 for non-VPN-core hosts raises routing concern.
- install_perm_anomaly api small_install_high_perm=true: only 10 installs with proxy (HIGH-tier) permission — tail attack surface.
- no_csp manifest csp_present=false on MV3; no content_security_policy declared — v2 calibration +2.0 network applied.
Permissions Breakdown
- proxy high Routes all browser traffic through attacker-controlled proxy; highest-impact VPN-class permission.
- https://stealthpath.space/* high Unknown third-party domain receives proxy config and is the install-redirect target.
- https://cloudflare-dns.com/* low Public DNS-over-HTTPS endpoint; expected for VPN DNS resolution.
- https://dns.google/* low Public DNS-over-HTTPS endpoint; expected for VPN DNS resolution.
Pillar Scores
Permissions7.00
Reputation8.50
Network5.50
Webstore5.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 13:26
Listing SHA
8405c29f77ef…
Force block
— not fired
Score recovered
no
Elapsed
—