Протон VPN
hhebjfghjolapmbfpjeppcchgglanfgh
Risk Score
6.17
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- proxy permission gives full network traffic interception capability to unverified free-webmail developer
- Privacy policy is Google's generic policy — not scoped to this extension, data collection and 3rd-party sharing admitted
- install_url_hijack: onInstalled opens 3rd-party URL (app.getmyxa.com) — monetization/tracking shell pattern
- Developer is anonymous (no name, free Gmail, no business domain) with only 20 installs — tail attack surface
- External JS host app.getmyxa.com (NL/RU geo) unknown; proxy extension contacting unknown host is critical risk
Evidence
- proxy_permission_high_risk manifest proxy declared — routes all browser traffic through extension-controlled servers; extremely high capability for anonymous dev.
- install_url_hijack store install_url_hijack=true targeting app.getmyxa.com; monetization/tracking shell behavior on install.
- free_webmail_no_dev_name store Developer email imawocigi29@gmail.com, no developer name, no business domain — reputation floor triggered.
- generic_google_privacy_policy store Privacy policy is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
- external_js_hosts crx JS contacts app.getmyxa.com (NL/RU) and t.me; unknown third-party endpoints for a VPN extension.
- small_install_high_perm store Only 20 installs with HIGH-tier proxy permission — tail attack surface anomaly flagged.
- no_csp manifest content_security_policy is null; MV3 has strict defaults but absence still notable alongside external hosts.
- brand_impersonation_risk store Title 'Протон VPN' mimics ProtonVPN brand; brand_mention.is_impersonation=false per classifier but unverified dev uses brand name.
Permissions Breakdown
- proxy high Full control over all browser network traffic; can redirect all requests to attacker-controlled servers.
Pillar Scores
Permissions7.00
Reputation8.50
Network3.00
Webstore5.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 14:11
Listing SHA
849824ccf7f0…
Force block
— not fired
Score recovered
no
Elapsed
—