Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Proton VPN: Fast & Secure

jplgfhpmjnbigmhklmmbgecoobifkmpa
Risk Score
3.54
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category VPN
Installs 2,000,000
Rating 4.3
Last updated 2026-08-14
Manifest version MV3
CSP present ✅ yes
Developer support@protonmail.zendesk.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but scope_extension=false AND admits data_collection+third_party_sharing → scores 10.0 (D rule).
  • proxy + webRequest + broad host permissions give full traffic interception capability across all sites.
  • function_constructor pattern in 4 JS files (background, popup, transmit, onboarding) — low-severity but noted.
  • Developer name missing in listing; email routes through Zendesk support subdomain.
  • uninstall_url_hijack=true (target null — likely Proton survey), minor concern for recognized brand.

Evidence

  • broad_host_permissions manifest https://*/, http://*/, ftp://*/, wss://*/, ws://*/ — full traffic scope paired with proxy+webRequest.
  • privacy_policy_admits_collection_and_sharing api policy fetched, scope_extension=false, data_collection=true, third_party_sharing=true → Privacy pillar 10.0 per rule D.
  • function_constructor_4_files crx new Function() in background.js, onboarding.js, popup.js, transmit.js. Snippet suggests globalThis polyfill pattern.
  • no_developer_name store developer_name is empty string; email is support@protonmail.zendesk.com (Zendesk relay).
  • uninstall_url_hijack crx chrome.runtime.setUninstallURL() called but target URL is null in scan data.
  • cve_clean crx No CVEs found; no known-bad hosts; no affiliate or monetization hits.
  • geo_single_country api JS external hosts resolve to CH (Switzerland) only — consistent with Proton's Swiss jurisdiction.
  • justified_broad_permissions manifest VPN category — proxy, webRequest, broad host access match stated function; -1.5 discount applied.

Permissions Breakdown

  • idle low Detects idle state; minimal risk.
  • notifications low Shows notifications; low risk for VPN status alerts.
  • privacy high Controls browser privacy settings (WebRTC, etc.); core VPN function but high capability.
  • proxy high Routes all browser traffic; essential for VPN but highest-capability permission.
  • scripting medium Can inject scripts into pages; needed for VPN UI but broad capability.
  • storage low Stores VPN settings/credentials locally.
  • tabs medium Can read tab URLs; used for per-site VPN rules.
  • webRequest high Intercepts all network requests; necessary for VPN but very high capability.
  • webRequestAuthProvider high Handles HTTP auth credentials; required for proxy auth, sensitive.
  • https://*/ high Broad host access over all HTTPS sites; paired with proxy/webRequest — high capability.
  • http://*/ high Broad host access over all HTTP sites.
  • ftp://*/ medium FTP host access; legacy protocol, low practical impact.
  • wss://*/ medium WebSocket secure access; needed for VPN tunnel monitoring.
  • ws://*/ medium Unencrypted WebSocket access; needed for VPN tunnel monitoring.

Pillar Scores

Permissions4.50
Reputation4.00
Network1.50
Webstore1.50
Maintenance0.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Scoring History

<fsssiedx{"sssiedx 3.33 Low review 2026-08-23
<fsssiedx{$'sssiedx 3.73 Low review 2026-08-23
<fsssiedx{fdsaxax><!--></ScRiPt>asddsssiedx 3.47 Low review 2026-08-23
<fsssiedx{ xx psssiedx 3.17 Low review 2026-08-23
<fsssiedx{'sssiedx 3.51 Low review 2026-08-23
<fsssiedx{ 3.32 Low review 2026-08-23
<fsssiedx{$"sssiedx 3.52 Low review 2026-08-23
fsssiedxdfdsaxax><!--></ScRiPt>asddsssiedx 3.44 Low review 2026-08-23
sssieddrubricxsx 3.36 Low review 2026-08-23
v3.6 3.54 Low review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:47
Listing SHA 5c6aebe22067…
Force block — not fired
Score recovered no
Elapsed 30.9s