Radmin ВПН-Защита данных
jgmokihhodhebpmcbamcjgjbpkngngap
Risk Score
5.36
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- proxy permission routes ALL browser traffic through unverified servers (app.myxavpn.pro, silashield.space) with no accountability.
- Privacy policy is Google's own account policy — completely unscoped to this extension; admits data collection and 3rd-party sharing.
- Free-webmail dev (asdro1905@gmail.com), no dev name, no verified publisher — no accountability for proxy traffic handling.
- install_url_hijack present; extension opens external URL on install, consistent with referral/affiliate or silent onboarding.
- 4 JS external hosts across 4 countries (CA, NL, RU, US) including silashield.space — unknown domain handling proxied traffic.
Evidence
- proxy_permission manifest proxy declared — can intercept and redirect all browser network traffic through any server.
- external_js_hosts crx app.myxavpn.pro, silashield.space, t.me contacted; silashield.space is unknown/unverifiable domain handling VPN traffic.
- privacy_policy_google_generic store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true — D clause applies: +10.
- free_webmail_no_devname store Developer asdro1905@gmail.com, no developer_name, no verified publisher — floor reputation >= 7.5.
- install_url_hijack crx install_url_hijack=true; extension opens 3rd-party URL on install — referral or silent tracking pattern.
- geo_diversity api JS hosts span 4 countries (CA, NL, RU, US); +1.5 Network per v3.3 rule 14 (VPN category exempts this).
- tail_attack_small_install_high_perm store Only 3 installs, has HIGH-tier permission (proxy); small_install_high_perm=true → +1.5 Webstore.
- no_csp manifest csp_present=false on MV3; no additional MV2 penalty but no CSP safety net for inline/remote script.
Permissions Breakdown
- proxy high Redirects all browser traffic through attacker-controlled servers; fundamental VPN mechanism but extremely powerful.
- https://cloudflare-dns.com/* medium DoH resolver access; consistent with VPN/privacy tool DNS-over-HTTPS use.
- https://dns.google/* medium DoH resolver access; consistent with VPN use but adds a second external DNS endpoint.
Pillar Scores
Permissions4.50
Reputation8.50
Network5.50
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 13:38
Listing SHA
f37131f7cfda…
Force block
— not fired
Score recovered
no
Elapsed
—