Free VPN for Chrome: Secure VPN Proxy in One Click
hklhhkchffegjfojbofhfkckjidfbjhe
Risk Score
5.55
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- proxy+webRequest+<all_urls>: full traffic interception capability on every site the user visits
- Privacy policy is Google's generic policy — not scoped to this extension, admits data collection and 3rd-party sharing
- Free-webmail developer (gmail) with no verified publisher badge or business domain raises accountability concerns
- scripting+<all_urls> allows arbitrary JS injection into any page; high capability for a 3,000-install unknown developer
- Privacy policy links to Google Account policy — developer data practices completely undisclosed
Evidence
- proxy+<all_urls>+webRequest manifest Triple HIGH-risk combo: proxy routes all traffic, webRequest observes it, <all_urls> applies everywhere.
- generic_privacy_policy store Privacy URL is myaccount.google.com/privacypolicy — Google's own policy, not extension-specific.
- privacy_classification_scope_false api scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 Privacy pillar (v3.5 rule D).
- free_webmail_developer store Developer email candybitcompany+support@gmail.com; no verified publisher; no business domain.
- dom_sink_innerhtml crx innerHTML assignment found in assets/index-BKA750bI.js; CSP present so +0.5 only.
- justified_broad_perm_VPN manifest Category=VPN justifies broad host/proxy/webRequest; -1.5 discount applied but proxy+webRequest combo still high.
- no_cve_findings crx cve_findings_raw is empty; CVE pillar = 0.0.
- operator_cluster_singleton api sibling_count=0; no cluster penalty applied.
Permissions Breakdown
- tabs medium Allows reading tab URLs/titles — moderate privacy surface for a VPN.
- activeTab low Scoped to user-invoked interaction; low standalone risk.
- background low Persistent background context; expected for a VPN.
- scripting high Can inject scripts into any page via host_permissions=<all_urls>.
- webRequest high Can observe all network requests across all URLs — very broad surveillance surface.
- webRequestAuthProvider high Can intercept auth challenges; enables credential interception if abused.
- declarativeNetRequest medium Can block/redirect network requests; appropriate for VPN but powerful.
- storage low Local data persistence; low risk in isolation.
- proxy high Routes all browser traffic through attacker-controlled server if compromised.
- <all_urls> high Broad host access amplifies webRequest, scripting, and proxy to every site.
Pillar Scores
Permissions8.50
Reputation7.50
Network2.00
Webstore2.50
Maintenance0.00
Privacy10.00
Code Quality0.50
CVE Exposure0.00
Scoring History
| fsssiedxn83b226dcza xx pn83b226dczsssiedx | 7.30 | High | review | 2026-09-12 |
| sssiedn1d456132dp727562726963xsx | 6.17 | High | block | 2026-09-12 |
| v3.6 | 5.55 | Medium | review | 2026-08-28 |
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 10:45
Listing SHA
977b21bcd5e9…
Force block
— not fired
Score recovered
no
Elapsed
—