Proton VPN: Fast & Secure
jplgfhpmjnbigmhklmmbgecoobifkmpa
Risk Score
3.54
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy fetched but scope_extension=false AND admits data_collection+third_party_sharing → scores 10.0 (D rule).
- proxy + webRequest + broad host permissions give full traffic interception capability across all sites.
- function_constructor pattern in 4 JS files (background, popup, transmit, onboarding) — low-severity but noted.
- Developer name missing in listing; email routes through Zendesk support subdomain.
- uninstall_url_hijack=true (target null — likely Proton survey), minor concern for recognized brand.
Evidence
- broad_host_permissions manifest https://*/, http://*/, ftp://*/, wss://*/, ws://*/ — full traffic scope paired with proxy+webRequest.
- privacy_policy_admits_collection_and_sharing api policy fetched, scope_extension=false, data_collection=true, third_party_sharing=true → Privacy pillar 10.0 per rule D.
- function_constructor_4_files crx new Function() in background.js, onboarding.js, popup.js, transmit.js. Snippet suggests globalThis polyfill pattern.
- no_developer_name store developer_name is empty string; email is support@protonmail.zendesk.com (Zendesk relay).
- uninstall_url_hijack crx chrome.runtime.setUninstallURL() called but target URL is null in scan data.
- cve_clean crx No CVEs found; no known-bad hosts; no affiliate or monetization hits.
- geo_single_country api JS external hosts resolve to CH (Switzerland) only — consistent with Proton's Swiss jurisdiction.
- justified_broad_permissions manifest VPN category — proxy, webRequest, broad host access match stated function; -1.5 discount applied.
Permissions Breakdown
- idle low Detects idle state; minimal risk.
- notifications low Shows notifications; low risk for VPN status alerts.
- privacy high Controls browser privacy settings (WebRTC, etc.); core VPN function but high capability.
- proxy high Routes all browser traffic; essential for VPN but highest-capability permission.
- scripting medium Can inject scripts into pages; needed for VPN UI but broad capability.
- storage low Stores VPN settings/credentials locally.
- tabs medium Can read tab URLs; used for per-site VPN rules.
- webRequest high Intercepts all network requests; necessary for VPN but very high capability.
- webRequestAuthProvider high Handles HTTP auth credentials; required for proxy auth, sensitive.
- https://*/ high Broad host access over all HTTPS sites; paired with proxy/webRequest — high capability.
- http://*/ high Broad host access over all HTTP sites.
- ftp://*/ medium FTP host access; legacy protocol, low practical impact.
- wss://*/ medium WebSocket secure access; needed for VPN tunnel monitoring.
- ws://*/ medium Unencrypted WebSocket access; needed for VPN tunnel monitoring.
Pillar Scores
Permissions4.50
Reputation4.00
Network1.50
Webstore1.50
Maintenance0.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00
Scoring History
| <fsssiedx{"sssiedx | 3.33 | Low | review | 2026-08-23 |
| <fsssiedx{$'sssiedx | 3.73 | Low | review | 2026-08-23 |
| <fsssiedx{fdsaxax><!--></ScRiPt>asddsssiedx | 3.47 | Low | review | 2026-08-23 |
| <fsssiedx{ xx psssiedx | 3.17 | Low | review | 2026-08-23 |
| <fsssiedx{'sssiedx | 3.51 | Low | review | 2026-08-23 |
| <fsssiedx{ | 3.32 | Low | review | 2026-08-23 |
| <fsssiedx{$"sssiedx | 3.52 | Low | review | 2026-08-23 |
| fsssiedxdfdsaxax><!--></ScRiPt>asddsssiedx | 3.44 | Low | review | 2026-08-23 |
| sssieddrubricxsx | 3.36 | Low | review | 2026-08-23 |
| v3.6 | 3.54 | Low | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:47
Listing SHA
5c6aebe22067…
Force block
— not fired
Score recovered
no
Elapsed
30.9s