Free VPN for Chrome - VPN Proxy VeePN
majdfhpaihoncoakbjgbdhglocklcgno
Risk Score
6.03
Risk Level:
High
Recommendation:
🚫 BLOCK
FORCE-BLOCK
Top Risks
- FORCE BLOCK: management + broad host access — extension can disable security tools AND has full traffic-routing capability.
- Privacy policy fetched but scope_extension=false AND data_collection=true AND third_party_sharing=true → admits data collection/sharing without scoping to this extension (max privacy score).
- Extremely high-capability permission stack: proxy + cookies + webRequest + privacy + management + <all_urls> — can intercept, reroute, and harvest all browser traffic.
- Uninstall URL hijack detected; extension registers a third-party URL on uninstall.
- management permission allows this extension to enumerate and disable other installed extensions.
Evidence
- permissions_high_capability manifest proxy+cookies+webRequest+privacy+management+<all_urls> — full traffic interception and extension control stack.
- privacy_policy_generic api scope_extension=false, data_collection=true, third_party_sharing=true → admits broad sharing without extension scope.
- uninstall_url_hijack crx uninstall_url_hijack=true; redirects user to third-party URL on uninstall.
- verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; discounts capped due to monetization_hits.
- monetization_hits crx Google Analytics telemetry endpoint present in js_external_hosts.
- broad_external_hosts crx 12 external hosts including split-tool.com, AWS Lambda URL, amplitude.com, fake-veepn.com.
- dom_xss_sinks crx Two innerHTML-from-variable findings in bundled JS; CSP is present so elevated-severity rule does not fully trigger.
- high_install_count store 14,000,000 installs; blast radius is very large if any compromise occurs.
Permissions Breakdown
- storage low Stores settings locally; minimal risk.
- proxy high Can route all browser traffic through arbitrary servers.
- tabs medium Can read tab URLs and titles across all sites.
- cookies high Access to all cookies; paired with <all_urls> this is critical.
- notifications low Push notifications; low standalone risk.
- webRequest high Intercept and observe all network requests across all URLs.
- webRequestAuthProvider high Can supply auth credentials for network requests.
- privacy high Can alter Chrome privacy/network settings (proxy, DoH, etc.).
- management high Can enumerate, disable, or uninstall other extensions.
- <all_urls> (host) high Full host access; compounds cookies, proxy, webRequest risk.
Pillar Scores
Permissions8.00
Reputation2.00
Network3.50
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality1.00
CVE Exposure0.00
Scoring History
| sssiednfb9f1611dp727562726963xsx | 5.84 | Medium | block | 2026-08-30 |
| <fsssiedxi$'sssiedx | 5.43 | Medium | block | 2026-08-17 |
| <fsssiedxa sssiedx | 3.77 | Low | block | 2026-08-17 |
| fsssiedx<sssiedx | 3.77 | Low | block | 2026-08-17 |
| <fsssiedxa xx psssiedx | 6.47 | High | block | 2026-08-13 |
| <fsssiedxa$'sssiedx | 5.46 | Medium | block | 2026-08-13 |
| <fsssiedxa"sssiedx | 5.37 | Medium | block | 2026-08-13 |
| <fsssiedxa'sssiedx | 5.09 | Medium | block | 2026-08-13 |
| <fsssiedxa$"sssiedx | 5.72 | Medium | block | 2026-08-13 |
| <fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 5.60 | Medium | block | 2026-08-13 |
| <fsssiedxa'sssiedx | 5.01 | Medium | block | 2026-08-13 |
| <fsssiedxa | 5.08 | Medium | block | 2026-08-13 |
| fsssiedxa<sssiedx | 5.03 | Medium | block | 2026-08-13 |
| fsssiedxcfdsaxax><!--></ScRiPt>asddsssiedx | 3.72 | Low | block | 2026-07-28 |
| sssieddrubricxsx | 5.24 | Medium | block | 2026-07-28 |
| v3.6 | 6.03 | High | block | 2026-06-16 |
| v3.4-rev | 4.22 | Medium | review | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:53
Listing SHA
7ad198bd3ff5…
Force block
🚫 fired
Score recovered
no
Elapsed
28.2s