Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Radmin ВПН-Защита данных

jgmokihhodhebpmcbamcjgjbpkngngap
Risk Score
5.36
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VPN
Installs 3
Rating
Last updated 2026-06-27 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer asdro1905@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission routes ALL browser traffic through unverified servers (app.myxavpn.pro, silashield.space) with no accountability.
  • Privacy policy is Google's own account policy — completely unscoped to this extension; admits data collection and 3rd-party sharing.
  • Free-webmail dev (asdro1905@gmail.com), no dev name, no verified publisher — no accountability for proxy traffic handling.
  • install_url_hijack present; extension opens external URL on install, consistent with referral/affiliate or silent onboarding.
  • 4 JS external hosts across 4 countries (CA, NL, RU, US) including silashield.space — unknown domain handling proxied traffic.

Evidence

  • proxy_permission manifest proxy declared — can intercept and redirect all browser network traffic through any server.
  • external_js_hosts crx app.myxavpn.pro, silashield.space, t.me contacted; silashield.space is unknown/unverifiable domain handling VPN traffic.
  • privacy_policy_google_generic store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true — D clause applies: +10.
  • free_webmail_no_devname store Developer asdro1905@gmail.com, no developer_name, no verified publisher — floor reputation >= 7.5.
  • install_url_hijack crx install_url_hijack=true; extension opens 3rd-party URL on install — referral or silent tracking pattern.
  • geo_diversity api JS hosts span 4 countries (CA, NL, RU, US); +1.5 Network per v3.3 rule 14 (VPN category exempts this).
  • tail_attack_small_install_high_perm store Only 3 installs, has HIGH-tier permission (proxy); small_install_high_perm=true → +1.5 Webstore.
  • no_csp manifest csp_present=false on MV3; no additional MV2 penalty but no CSP safety net for inline/remote script.

Permissions Breakdown

  • proxy high Redirects all browser traffic through attacker-controlled servers; fundamental VPN mechanism but extremely powerful.
  • https://cloudflare-dns.com/* medium DoH resolver access; consistent with VPN/privacy tool DNS-over-HTTPS use.
  • https://dns.google/* medium DoH resolver access; consistent with VPN use but adds a second external DNS endpoint.

Pillar Scores

Permissions4.50
Reputation8.50
Network5.50
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 13:38
Listing SHA f37131f7cfda…
Force block — not fired
Score recovered no
Elapsed