Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

DotVPN: Fast & Private VPN

kpiecbcckbofpmkkkdibbllpinceiihk
Risk Score
5.73
Risk Level: Medium
Recommendation: 🚫 BLOCK FORCE-BLOCK
Category VPN
Installs 500,000
Rating 3.7
Last updated 2026-06-15
Manifest version MV3
CSP present ❌ no
Developer vpn.chrome@dotvpn.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • FORCE BLOCK: management + broad host access — extension can disable security tools AND has full traffic-routing capability.
  • Privacy policy fetched, scoped to generic domain (not this extension), admits data collection AND third-party sharing — scores maximum 10.
  • proxy + webRequest + <all_urls> + management: extreme capability triad can reroute all traffic, observe requests, and suppress competing extensions.
  • No CSP present (MV3 default only); innerHTML XSS sink in popup with no policy guard increases exploit surface.
  • No developer name listed; verified_publisher is true but no display name raises accountability gap.

Evidence

  • privacy_policy_generic_with_collection_and_3p_sharing api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true — triggers Privacy +10.0 (v3.5 rule D).
  • high_perm_triad_proxy_webRequest_management manifest proxy+webRequest+management+<all_urls> all declared; VPN discount applied (-1.5) but residual score remains high at 7.5.
  • no_csp manifest content_security_policy is null; MV3 has strict default but no explicit CSP raises code-quality risk for innerHTML finding.
  • dom_innerhtml_no_csp crx dom_sink_innerhtml_userctrl in popup/assets/icons.js; csp_present=false triggers +2.0 code quality (FIX B).
  • verified_publisher_active_domain store verified_publisher=true, dotvpn.com resolves, months_since_update=0 — discount applies without 0c cap conditions.
  • no_developer_name store developer_name is empty string; email domain dotvpn.com exists but no display name shown.
  • js_external_hosts crx 2 external hosts: dot-security-systems.com, dotvpn.com — both appear dev-controlled; no bad/monetization hits.
  • no_cve_findings crx cve_findings_raw is empty; jquery 4.0.0 has no known CVEs — CVE pillar = 0.0.

Permissions Breakdown

  • proxy high Full proxy control — can route all browser traffic through arbitrary servers.
  • webRequest high Intercept and observe all network requests across all URLs.
  • management high Can enumerate, enable, disable or uninstall other extensions.
  • <all_urls> high Host permission — access to every site the user visits, required for VPN/proxy function.
  • scripting medium Can inject scripts into pages; paired with <all_urls> is powerful.
  • alarms low Scheduled tasks; low intrinsic risk.
  • storage low Local extension storage; low intrinsic risk.

Pillar Scores

Permissions7.50
Reputation4.00
Network4.00
Webstore1.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:50
Listing SHA 24532b2585dd…
Force block 🚫 fired
Score recovered no
Elapsed 29.0s