Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Free VPN for Chrome: Secure VPN Proxy in One Click

hklhhkchffegjfojbofhfkckjidfbjhe
Risk Score
5.55
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VPN
Installs 3,000
Rating 3.5
Last updated 2026-05-12 (4 months ago)
Manifest version MV3
CSP present ✅ yes
Developer candybitcompany+support@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy+webRequest+<all_urls>: full traffic interception capability on every site the user visits
  • Privacy policy is Google's generic policy — not scoped to this extension, admits data collection and 3rd-party sharing
  • Free-webmail developer (gmail) with no verified publisher badge or business domain raises accountability concerns
  • scripting+<all_urls> allows arbitrary JS injection into any page; high capability for a 3,000-install unknown developer
  • Privacy policy links to Google Account policy — developer data practices completely undisclosed

Evidence

  • proxy+<all_urls>+webRequest manifest Triple HIGH-risk combo: proxy routes all traffic, webRequest observes it, <all_urls> applies everywhere.
  • generic_privacy_policy store Privacy URL is myaccount.google.com/privacypolicy — Google's own policy, not extension-specific.
  • privacy_classification_scope_false api scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 Privacy pillar (v3.5 rule D).
  • free_webmail_developer store Developer email candybitcompany+support@gmail.com; no verified publisher; no business domain.
  • dom_sink_innerhtml crx innerHTML assignment found in assets/index-BKA750bI.js; CSP present so +0.5 only.
  • justified_broad_perm_VPN manifest Category=VPN justifies broad host/proxy/webRequest; -1.5 discount applied but proxy+webRequest combo still high.
  • no_cve_findings crx cve_findings_raw is empty; CVE pillar = 0.0.
  • operator_cluster_singleton api sibling_count=0; no cluster penalty applied.

Permissions Breakdown

  • tabs medium Allows reading tab URLs/titles — moderate privacy surface for a VPN.
  • activeTab low Scoped to user-invoked interaction; low standalone risk.
  • background low Persistent background context; expected for a VPN.
  • scripting high Can inject scripts into any page via host_permissions=<all_urls>.
  • webRequest high Can observe all network requests across all URLs — very broad surveillance surface.
  • webRequestAuthProvider high Can intercept auth challenges; enables credential interception if abused.
  • declarativeNetRequest medium Can block/redirect network requests; appropriate for VPN but powerful.
  • storage low Local data persistence; low risk in isolation.
  • proxy high Routes all browser traffic through attacker-controlled server if compromised.
  • <all_urls> high Broad host access amplifies webRequest, scripting, and proxy to every site.

Pillar Scores

Permissions8.50
Reputation7.50
Network2.00
Webstore2.50
Maintenance0.00
Privacy10.00
Code Quality0.50
CVE Exposure0.00

Scoring History

fsssiedxn83b226dcza xx pn83b226dczsssiedx 7.30 High review 2026-09-12
sssiedn1d456132dp727562726963xsx 6.17 High block 2026-09-12
v3.6 5.55 Medium review 2026-08-28

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 10:45
Listing SHA 977b21bcd5e9…
Force block — not fired
Score recovered no
Elapsed