Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

CyberGhost VPN – Proxy for Chrome

ffbkglfijbcbgblgflchnbphjdllaogb
Risk Score
4.32
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VPN
Installs 800,000
Rating 3.2
Last updated 2025-09-23 (9 months ago)
Manifest version MV3
CSP present ✅ yes
Developer support@cyberghost.ro
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetch failed — cannot verify data handling; scored as no policy.
  • proxy + <all_urls> combination routes all browser traffic; critical if extension compromised.
  • Rating 3.2 with 800K installs suggests user-reported issues; no review red-flags detected in scan.
  • No developer name listed in store; identity accountability gap.
  • External JS host (react.dev) present; benign but adds minor supply-chain surface.

Evidence

  • proxy+all_urls manifest proxy permission + <all_urls> host access; justified for VPN but grants full traffic routing capability.
  • privacy_policy_fetch_failed api Privacy policy URL returned HTTPError; classification unavailable; scored at +10.0 (fetched==false).
  • low_rating store Rating 3.2 across large install base (800K); no review red-flags matched in automated scan.
  • no_developer_name store developer_name is empty; email support@cyberghost.ro links to cyberghost.ro which resolves.
  • csp_present_mv3 manifest CSP restricts script-src to 'self'; MV3 enforces strict defaults. No unsafe-eval/inline.
  • clean_code_scan crx code_findings_raw empty; obfuscation_score 0.0; only 2 JS files scanned.
  • no_cve_findings crx No CVEs detected in bundled libraries; js_libraries_detected is empty.
  • maintenance_9mo store Last updated September 2025; 9 months ago; falls in 3-6mo band (+1.5).

Permissions Breakdown

  • storage low Stores extension settings locally; low risk.
  • tabs medium Can read tab URLs and titles; needed for VPN routing decisions.
  • proxy high Routes all browser traffic; core to VPN function but high-impact if abused.
  • <all_urls> high Broad host access required for proxy routing but significant capability surface.

Pillar Scores

Permissions5.50
Reputation5.50
Network2.00
Webstore2.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:33
Listing SHA b64f158eb35f…
Force block — not fired
Score recovered no
Elapsed 20.9s