Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Free VPN & Proxy For Chrome - VPNLY

lneaocagcijjdpkcabeanfpdbmapcjjg
Risk Score
5.43
Risk Level: Medium
Recommendation: 🚫 BLOCK FORCE-BLOCK
Category VPN
Installs 1,000,000
Rating 4.6
Last updated 2026-05-27 (3 months ago)
Manifest version MV3
CSP present ✅ yes
Developer support@vpnly.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • FORCE BLOCK: management + broad host access — extension can disable security tools AND has full traffic-routing capability.
  • Privacy policy is Google's generic policy (scope_extension=false, admits data_collection+third_party_sharing) — scores +10.0 per v3.5 rule D.
  • proxy + webRequest + <all_urls> means all browser traffic can be intercepted and rerouted; management permission adds lateral extension control.
  • Uninstall URL hijack detected — extension registers a 3rd-party uninstall redirect (+3.0 Webstore).
  • External host api.kurva.cc is an opaque non-branded endpoint for a 1M-install VPN; no threat-intel clearance available.

Evidence

  • privacy_policy_generic_google store Privacy URL points to myaccount.google.com/privacypolicy — Google's own policy, not scoped to VPNLY; scope_extension=false, data_collection=true, third_party_sharing=true.
  • uninstall_url_hijack crx uninstall_url_hijack=true; redirects user on uninstall to undisclosed 3rd-party URL.
  • high_permissions_proxy_management manifest proxy + webRequest + webRequestAuthProvider + management + <all_urls>; management is not justified for a VPN.
  • external_host_kurva_cc crx js_external_hosts includes api.kurva.cc — opaque domain with no brand association for a 1M-install VPN.
  • verified_publisher store verified_publisher=true; -1.0 discount applied to reputation (not full -3.0 due to capability gate: proxy+webRequest are HIGH-impact).
  • install_count_1m store 1,000,000 installs; +1.0+1.0+0.5 webstore reach; broad blast radius.
  • justified_broad_permission_discount manifest Category=VPN; -1.5 justified-broad-permission discount applied to permissions pillar for proxy+webRequest+<all_urls>.
  • cve_clean crx cve_findings_raw=[] and code_findings_raw=[]; no JS libraries detected; obfuscation_score=0.0.

Permissions Breakdown

  • proxy high Can route all browser traffic through attacker-controlled server; core VPN function but very high-impact.
  • webRequest high Intercepts all HTTP/S requests across all URLs; combined with proxy creates full traffic visibility.
  • webRequestAuthProvider high Can handle authentication credentials for network requests; credential exposure risk.
  • management high Can list, enable, disable, or uninstall other extensions; elevated lateral capability.
  • tabs medium Accesses tab URLs, titles, and navigation events across all browser tabs.
  • storage low Local key-value storage; standard for settings persistence.
  • offscreen low Creates offscreen documents for background processing; minimal direct risk.
  • <all_urls> high Broad host access paired with proxy+webRequest; ×1.2 amplifier applies.

Pillar Scores

Permissions7.50
Reputation2.00
Network2.00
Webstore3.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Scoring History

<fsssiedxa'sssiedx 6.38 High block 2026-08-22
<fsssiedxa sssiedx 6.49 High block 2026-08-22
<fsssiedxa&#x27;sssiedx 6.22 High block 2026-08-22
fsssiedxa<sssiedx 5.27 Medium block 2026-08-22
<fsssiedxi'sssiedx 6.14 High block 2026-08-11
<fsssiedxi&#x22;sssiedx 6.24 High block 2026-08-11
<fsssiedxa"sssiedx 6.34 High block 2026-08-11
<fsssiedxa&#x22;sssiedx 4.94 Medium block 2026-08-11
<fsssiedxdfdsaxax><!--></ScRiPt>asddsssiedx 4.98 Medium block 2026-07-30
<fsssiedxd$'sssiedx 5.07 Medium block 2026-07-30
xx pfsssiedxdfdsaxax><!--></ScRiPt>asddsssiedx 6.12 High block 2026-07-30
xx pfsssiedxd$"sssiedx 6.27 High block 2026-07-30
&#x22;fsssiedxd'sssiedx 6.11 High block 2026-07-30
&#x22;fsssiedxdfdsaxax><!--></ScRiPt>asddsssiedx 6.21 High block 2026-07-30
5.87 Medium block 2026-07-30
$"fsssiedxdfdsaxax><!--></ScRiPt>asddsssiedx 5.79 Medium block 2026-07-30
$"fsssiedxd$'sssiedx 6.22 High block 2026-07-30
fsssiedxd$"sssiedx 5.03 Medium block 2026-07-30
<fsssiedx{$"sssiedx 6.28 High block 2026-07-30
<fsssiedxi 6.56 High block 2026-07-30
<fsssiedxi$'sssiedx 6.79 High block 2026-07-30
<fsssiedxa xx psssiedx 6.01 High block 2026-07-30
<fsssiedxa$'sssiedx 6.55 High block 2026-07-30
<fsssiedxa$"sssiedx 6.55 High block 2026-07-28
<fsssiedxi$"sssiedx 6.17 High block 2026-07-28
<fsssiedx{fdsaxax><!--></ScRiPt>asddsssiedx 6.48 High block 2026-07-28
<fsssiedx{&#x27;sssiedx 6.26 High block 2026-07-28
fsssiedx<sssiedx 5.79 Medium block 2026-07-28
fsssiedxx'sssiedx 6.49 High block 2026-07-28
sssieddrubricxsx 5.00 Medium block 2026-07-28
v3.6 5.43 Medium block 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 06:28
Listing SHA 4d0af647c3a4…
Force block 🚫 fired
Score recovered no
Elapsed 26.8s