Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

DostupNet VPN — удобный доступ к сайтам и сервисам

eoolgeaiphoeoeldlmcholcdgdkldoem
Risk Score
5.56
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VPN
Installs 109
Rating 4.9
Last updated 2026-04-30 (5 months ago)
Manifest version MV3
CSP present ❌ no
Developer reshilipogolove@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission lets developer route ALL browser traffic through any server they control — full MITM capability.
  • Privacy policy is Google's generic account policy, not scoped to this extension; data practices undisclosed.
  • Developer is anonymous (no name, free-webmail only) with 109 installs — impossible to verify identity.
  • install_url_hijack detected: extension opens a third-party URL on install.
  • VPN category warrants justified-broad discount on permissions, but anonymous dev and generic policy negate trust.

Evidence

  • proxy_permission manifest proxy declared — can intercept and redirect all browser network traffic to attacker-controlled infrastructure.
  • install_url_hijack store install_url_hijack == true; extension opens a URL on install, classic monetization/tracking shell signal.
  • generic_privacy_policy store Privacy policy points to myaccount.google.com/privacypolicy — Google's own policy, not scoped to this VPN extension.
  • anonymous_developer store developer_name empty; email reshilipogolove@gmail.com (free webmail). No verified publisher, not featured.
  • small_install_high_perm api 109 installs with HIGH-tier proxy permission — tail attack surface flag raised.
  • no_csp manifest content_security_policy is null; MV3 provides some default but no explicit CSP declared.
  • privacy_classification api fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (D rule).
  • no_code_findings crx 2 JS files scanned, obfuscation_score=0.0, code_findings_raw empty — no active malicious code detected.

Permissions Breakdown

  • proxy high Can redirect all browser traffic through an arbitrary server — maximum MITM capability.
  • storage low Local key-value store; low standalone risk.

Pillar Scores

Permissions7.00
Reputation7.50
Network2.00
Webstore5.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 15:57
Listing SHA d93713ae1438…
Force block — not fired
Score recovered no
Elapsed