Jump VPN
ldhmimnchgkihniijggnhcanhphillnn
Risk Score
5.33
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- proxy permission allows complete traffic interception/redirection through developer-controlled infrastructure
- Privacy policy is Google's generic policy — not scoped to this extension; admits data collection and 3rd-party sharing
- Developer is anonymous (no name, free Gmail, no business domain); low accountability
- Install-time URL hijack observed; extension opens 3rd-party URL on install
- External JS hosts include app.getmyxa.com (unknown) and t.me (Telegram); unusual for a VPN extension
Evidence
- proxy_permission manifest proxy declared — routes all browser traffic; critical for VPN but high-risk from unverified dev.
- install_url_hijack crx install_url_hijack=true; extension opens external URL on install — phishing/affiliate monetization risk.
- generic_privacy_policy store Privacy URL is Google's own policy page, not scoped to Jump VPN; fetched=true but scope_extension=false.
- free_webmail_no_dev_name store Developer email kristi.tis@gmail.com, developer_name empty — no accountable identity.
- external_js_hosts crx JS contacts app.getmyxa.com (unknown) and t.me (Telegram); neither expected for a VPN extension.
- low_rating store Rating 1.0 with only 114 installs; indicates very poor user reception.
- small_install_high_perm_anomaly api install_perm_anomaly: small_install_high_perm=true — 114 installs with proxy (HIGH) permission.
- no_csp manifest content_security_policy is null; MV3 provides defaults but no explicit CSP hardening present.
Permissions Breakdown
- proxy high Can redirect all browser traffic through an attacker-controlled server; full network interception capability.
Pillar Scores
Permissions6.50
Reputation8.50
Network2.00
Webstore5.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 13:40
Listing SHA
029be9edb118…
Force block
— not fired
Score recovered
no
Elapsed
—