Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Free VPN For Chrome & Ad blocker — Planet VPN

hipncndjamdcmphkgngojegjblibadbe
Risk Score
5.63
Risk Level: Medium
Recommendation: 🚫 BLOCK FORCE-BLOCK
Category VPN
Installs 1,000,000
Rating 4.6
Last updated 2026-08-31 (1 months ago)
Manifest version MV3
CSP present ✅ yes
Developer support@freevpnplanet.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • FORCE BLOCK: management + broad host access — extension can disable security tools AND has full traffic-routing capability.
  • Privacy policy is Google's own policy (scope_extension=false, data_collection=true, third_party_sharing=true) — admits collection & sharing with no extension-specific scope.
  • proxy + <all_urls> + webRequest: can silently intercept and reroute all browser traffic; core VPN risk but extremely high-impact if compromised.
  • management permission allows disabling other extensions, including security tools — atypical for a VPN/adblocker.
  • Uninstall URL hijack detected — extension sets a third-party URL on uninstall.

Evidence

  • privacy_policy_mismatch store Privacy policy URL points to Google's own policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • uninstall_url_hijack crx uninstall_url_hijack=true; extension registers a URL on uninstall (target unknown).
  • high_capability_permissions manifest proxy+webRequest+scripting+management+privacy+<all_urls> — broad interception and control surface.
  • management_permission manifest management permission declared; can enumerate/disable other extensions, unusual for VPN category.
  • featured_by_google store is_featured_by_google=true; reduces reputation risk but does not explain policy or uninstall hijack.
  • no_code_findings crx code_findings_raw empty, obfuscation_score=0.0, no external JS hosts — clean scan.
  • no_cve_findings crx cve_findings_raw empty; no known-vulnerable libraries detected.
  • content_scripts_narrow manifest content_scripts scoped to freevpnplanet.com, freevpnplanet.net, planetvpnarab.com — not injected broadly.

Permissions Breakdown

  • proxy high Can route all browser traffic through attacker-controlled server; extremely high-impact for VPN.
  • webRequest high Intercepts all network requests across all URLs.
  • webRequestAuthProvider high Can intercept and supply authentication credentials for network requests.
  • privacy high Can alter privacy settings like WebRTC, DNS, etc.
  • management high Can enumerate, enable, or disable other installed extensions.
  • scripting high Can inject scripts into pages; paired with <all_urls> host permission.
  • history medium Full read/write access to browser history.
  • declarativeNetRequest medium Can block/redirect network requests declaratively.
  • declarativeNetRequestFeedback medium Can read which declarative rules matched requests.
  • tabs medium Access to tab URLs, titles, and navigation.
  • notifications low Can display desktop notifications; low standalone risk.
  • storage low Local data persistence; low standalone risk.
  • unlimitedStorage low Allows large local data storage.
  • offscreen low Can create hidden offscreen documents for background processing.
  • <all_urls> high Host permission grants access to all websites; amplifies proxy/scripting/webRequest.

Pillar Scores

Permissions7.50
Reputation3.50
Network2.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Scoring History

sssiednf9fa7695dp727562726963xsx 6.53 High block 2026-09-07
sssiednb45635c1dp727562726963xsx 6.27 High block 2026-09-06
xx pfsssiedxa sssiedx 6.73 High block 2026-08-16
'fsssiedxa"sssiedx 6.67 High block 2026-08-16
'fsssiedxa$'sssiedx 6.52 High block 2026-08-16
&#x22;fsssiedxa&#x27;sssiedx 6.57 High block 2026-08-16
&#x22;fsssiedxa$"sssiedx 6.22 High block 2026-08-16
fsssiedxa$'sssiedx 6.27 High block 2026-08-16
<fsssiedxa xx psssiedx 6.49 High block 2026-08-05
<fsssiedxa&#x22;sssiedx 6.28 High block 2026-08-05
<fsssiedxa"sssiedx 6.37 High block 2026-08-05
<fsssiedxa$"sssiedx 6.41 High block 2026-08-05
<fsssiedxa sssiedx 6.57 High block 2026-08-05
<fsssiedxa'sssiedx 6.39 High block 2026-08-05
<fsssiedxa$'sssiedx 6.19 High block 2026-08-05
fsssiedxa<sssiedx 6.34 High block 2026-08-05
<fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 6.44 High block 2026-08-05
xx pfsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 6.48 High block 2026-08-05
xx pfsssiedxa$"sssiedx 6.32 High block 2026-08-05
%22fsssiedxa sssiedx 6.48 High block 2026-08-05
'fsssiedxasssiedx 6.27 High block 2026-08-05
6.27 High block 2026-08-05
$"fsssiedxa&#x22;sssiedx 6.33 High block 2026-08-05
fsssiedxa$"sssiedx 6.38 High block 2026-08-05
sssieddrubricxsx 6.29 High block 2026-07-28
v3.6 5.63 Medium block 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-15 14:16
Listing SHA 6991281b6087…
Force block 🚫 fired
Score recovered no
Elapsed 24.4s