Vector VPN — простое подключение в один клик
jdpnclabfdjckoggcihhcfphomgcmfib
Risk Score
5.63
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- proxy permission routes ALL browser traffic through ironproxy.space/myxavpn.pro — unverified Russian-hosted endpoints
- Privacy policy is Google's generic policy (scope_extension=false, data_collection=true, third_party_sharing=true) — admits broad sharing with no extension scope
- Free-webmail dev (binoyihe32@gmail.com), no developer name, no verified publisher — near-zero accountability
- Install URL hijack opens ironproxy.space on install; JS contacts app.myxavpn.pro, ironproxy.space, t.me — 3 distinct external hosts
- 4 installs with high-tier proxy permission flags tail-attack-surface anomaly; unknown actors could target enterprise installs
Evidence
- proxy_permission manifest proxy declared — full traffic interception possible through ironproxy.space and app.myxavpn.pro (NL/RU hosted).
- install_url_hijack crx onInstalled opens https://ironproxy.space/ — third-party domain not controlled by a verified developer.
- generic_privacy_policy store Privacy URL is Google's account policy; scope_extension=false, data_collection=true, third_party_sharing=true — D clause applies → +10.0.
- free_webmail_no_devname store Dev email binoyihe32@gmail.com, developer_name empty, not verified publisher → Reputation floor >=7.5.
- js_external_hosts crx 3 external hosts: app.myxavpn.pro, ironproxy.space, t.me. Countries: NL, RU (country_count=2).
- install_perm_anomaly api 4 installs, has_high_tier_permission=true, small_install_high_perm=true.
- no_csp manifest csp_present=false on MV3; no content_security_policy declared.
- cve_findings_empty crx No CVEs found in bundled libraries; cve_findings_raw is empty.
Permissions Breakdown
- proxy high Can redirect all browser traffic through attacker-controlled servers; full network interception capability.
Pillar Scores
Permissions6.50
Reputation8.00
Network4.50
Webstore6.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 13:44
Listing SHA
c07b7ef98480…
Force block
— not fired
Score recovered
no
Elapsed
—