DotVPN: Fast & Private VPN
kpiecbcckbofpmkkkdibbllpinceiihk
Risk Score
5.73
Risk Level:
Medium
Recommendation:
🚫 BLOCK
FORCE-BLOCK
Top Risks
- FORCE BLOCK: management + broad host access — extension can disable security tools AND has full traffic-routing capability.
- Privacy policy fetched, scoped to generic domain (not this extension), admits data collection AND third-party sharing — scores maximum 10.
- proxy + webRequest + <all_urls> + management: extreme capability triad can reroute all traffic, observe requests, and suppress competing extensions.
- No CSP present (MV3 default only); innerHTML XSS sink in popup with no policy guard increases exploit surface.
- No developer name listed; verified_publisher is true but no display name raises accountability gap.
Evidence
- privacy_policy_generic_with_collection_and_3p_sharing api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true — triggers Privacy +10.0 (v3.5 rule D).
- high_perm_triad_proxy_webRequest_management manifest proxy+webRequest+management+<all_urls> all declared; VPN discount applied (-1.5) but residual score remains high at 7.5.
- no_csp manifest content_security_policy is null; MV3 has strict default but no explicit CSP raises code-quality risk for innerHTML finding.
- dom_innerhtml_no_csp crx dom_sink_innerhtml_userctrl in popup/assets/icons.js; csp_present=false triggers +2.0 code quality (FIX B).
- verified_publisher_active_domain store verified_publisher=true, dotvpn.com resolves, months_since_update=0 — discount applies without 0c cap conditions.
- no_developer_name store developer_name is empty string; email domain dotvpn.com exists but no display name shown.
- js_external_hosts crx 2 external hosts: dot-security-systems.com, dotvpn.com — both appear dev-controlled; no bad/monetization hits.
- no_cve_findings crx cve_findings_raw is empty; jquery 4.0.0 has no known CVEs — CVE pillar = 0.0.
Permissions Breakdown
- proxy high Full proxy control — can route all browser traffic through arbitrary servers.
- webRequest high Intercept and observe all network requests across all URLs.
- management high Can enumerate, enable, disable or uninstall other extensions.
- <all_urls> high Host permission — access to every site the user visits, required for VPN/proxy function.
- scripting medium Can inject scripts into pages; paired with <all_urls> is powerful.
- alarms low Scheduled tasks; low intrinsic risk.
- storage low Local extension storage; low intrinsic risk.
Pillar Scores
Permissions7.50
Reputation4.00
Network4.00
Webstore1.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:50
Listing SHA
24532b2585dd…
Force block
🚫 fired
Score recovered
no
Elapsed
29.0s