Onion Browser Button
fockhhgebmfjljjmjhbdgibcmofjbpca
Risk Score
5.18
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- proxy permission allows full traffic rerouting by any future malicious update from an unverifiable gmail developer.
- Free-webmail developer (gmail) with no verified business identity; no accountability path if extension is sold or compromised.
- install_url_hijack and uninstall_url_hijack flags set; targets unresolvable (null) but pattern is suspicious.
- Privacy policy scoped but lacks data-retention disclosure and silences third-party sharing.
- Rating 3.4 from a privacy/proxy tool; community dissatisfaction with a high-capability permission is a risk signal.
Evidence
- proxy_permission manifest proxy declared — can redirect all browser traffic; justified for TOR proxy tool but extreme if developer account is compromised.
- free_webmail_developer store Developer email sevina.lucia@gmail.com; no verified business domain; Reputation pillar floored at 7.5 per rubric.
- install_uninstall_url_hijack crx install_url_hijack=true and uninstall_url_hijack=true; targets are null so full impact unclear but pattern is risky.
- no_csp manifest content_security_policy is null; MV3 has strict default but absence of explicit CSP noted.
- privacy_policy_retention_missing api Policy fetched, scoped, no data_collection, but retention=false and third_party_silence=true; incomplete.
- external_hosts crx JS contacts check.torproject.org, github.com, webbrowsertools.com — 3 distinct domains, 2 countries (CA, IN).
- low_rating store Rating 3.4; community feedback below average for a security-category tool.
- no_verified_publisher store verified_publisher=false, is_featured_by_google=false; no trust anchors beyond the listing itself.
Permissions Breakdown
- proxy high Can redirect all browser traffic through attacker-controlled proxy; core risk for this extension type.
- storage low Stores local extension preferences; low standalone risk.
- notifications low Can display desktop notifications; low risk without host access.
- https://check.torproject.org/* medium Scoped host access to tor-check endpoint; matches stated function but adds network surface.
Pillar Scores
Permissions5.50
Reputation7.50
Network3.50
Webstore5.00
Maintenance3.50
Privacy6.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:35
Listing SHA
a086e97c8dc3…
Force block
— not fired
Score recovered
no
Elapsed
22.8s