Anonymous HTTP Proxy
meifgfdnekgimiclillpbogbblbfbaeg
Risk Score
5.04
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- proxy permission allows full rerouting of all browser traffic through developer-controlled infrastructure
- Privacy policy fetched but admits data collection and third-party sharing without scoping to this extension — highest privacy risk tier
- No developer name listed; low install count (197) with high-impact permission is a tail-attack-surface flag
- Extension stale at 17 months; verified-publisher cap applies due to months_since_update > 18 proximity and monetization-adjacent concerns
- External JS hosts include github.com and www.apache.org — unexpected for a proxy tool; warrants code review
Evidence
- proxy_permission manifest proxy declared — can intercept and reroute all browser HTTP/HTTPS traffic to any server.
- privacy_policy_scope_fail api Policy fetched (94k chars), scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 privacy.
- no_developer_name store developer_name is empty string; email-only identity support@getbehind.me.
- install_perm_anomaly api small_install_high_perm=true, tail_attack_surface=true; 197 installs with proxy permission.
- verified_publisher store verified_publisher=true; discount applied but capped due to months_since_update=17 approaching 18mo threshold.
- external_js_hosts crx js_external_hosts includes github.com and www.apache.org — unexpected for a proxy extension.
- low_rating store Rating 3.0; no review red flags detected (match_count=0).
- maintenance_stale store Last updated January 30 2025; months_since_update=17 → +3.5 maintenance score.
Permissions Breakdown
- proxy high Full proxy control — can reroute all browser traffic through attacker-controlled servers.
- storage low Stores extension config locally; low standalone risk.
- alarms low Scheduled task triggers; low risk in isolation.
Pillar Scores
Permissions5.50
Reputation5.00
Network2.00
Webstore4.50
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:54
Listing SHA
794651326ca6…
Force block
— not fired
Score recovered
no
Elapsed
18.9s