Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Myxa Connect

fcmecilpdddmffmnjhdmillmddahmfnh
Risk Score
5.44
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VPN
Installs 36
Rating 5.0
Last updated 2026-02-19 (7 months ago)
Manifest version MV3
CSP present ❌ no
Developer vale99505@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy URL unreachable (fetch error) — no verifiable data-handling disclosure for a proxy/VPN extension.
  • proxy permission allows complete rerouting of all browser traffic to arbitrary servers.
  • Developer is free-webmail (gmail), no developer name, no verified publisher — unaccountable operator.
  • Very low install count (36) with high-capability permission is a tail-attack-surface signal.
  • MV3 but no CSP; proxy control combined with unverifiable privacy policy warrants scrutiny.

Evidence

  • proxy_permission manifest proxy declared — full browser traffic routing control; matches VPN category but high-capability risk.
  • privacy_policy_fetch_failed api privacy_policy_classification.fetched=false (HTTPError); policy at myxavpn.com/privacy/ could not be verified.
  • free_webmail_developer store Developer email vale99505@gmail.com; no developer name; not verified publisher; not featured.
  • small_install_high_perm api install_perm_anomaly: 36 installs with high-tier proxy permission flagged as small_install_high_perm=true.
  • no_cve_findings crx cve_findings_raw empty; no known vulnerable libraries detected.
  • no_code_findings crx code_findings_raw empty; obfuscation_score=0.0; 2 JS files scanned with no exfil or eval indicators.
  • no_bad_hosts api threat_intel: bad_host_hits, monetization_hits, affiliate_hits all empty; no external JS hosts.
  • maintenance_3_6_months store months_since_update=7; falls in 6-12 month band (+3.5 maintenance score).

Permissions Breakdown

  • proxy high Allows full control of browser network routing; core VPN function but critical capability.
  • storage low Standard local data persistence; low standalone risk.

Pillar Scores

Permissions6.00
Reputation7.50
Network0.00
Webstore3.00
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 13:35
Listing SHA 86f83a58c613…
Force block — not fired
Score recovered no
Elapsed