VPN unlimited, free VPN with private browsing
nagcmbgoldfkmkiennnjpmfkfcpdgmbk
Risk Score
6.94
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- proxy + <all_urls> lets extension silently reroute all browser traffic through arbitrary servers — critical for unverified VPN.
- Developer is free-webmail gmail user with no verified business; no accountability for traffic interception.
- Privacy policy on Google Sites admits data collection and third-party sharing without scoping to this extension — effectively admits data sale.
- Last updated 47 months ago (Oct 2022); abandoned extension with HIGH-capability permissions is prime acquisition/compromise target.
- Bundled jquery@1.9.1 carries 3 medium XSS CVEs (unfixed); no CSP amplifies exploitability via jquery×no-CSP rule.
Evidence
- proxy + broad host permissions manifest proxy declared alongside *://*/* and <all_urls>; can intercept and reroute all HTTPS/HTTP traffic.
- free-webmail developer, no verified publisher store steven.dujardin67@gmail.com with no business domain; verified_publisher=false, is_featured=false.
- privacy policy admits collection + third-party sharing, not scoped to extension api scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 privacy (D rule).
- abandoned extension — 47 months since update store Last updated Oct 2022; >36 months triggers max maintenance score of 10.0.
- jquery@1.9.1 bundled with 3 medium CVEs, no CSP crx CVE-2015-9251, CVE-2019-11358, CVE-2020-11023; no content_security_policy; jquery<3.5+no-CSP amplifier applies.
- uninstall URL hijack present crx chrome.runtime.setUninstallURL() called; target null in scan but hijack flag true — +3.0 webstore.
- rating 2.4 — below 3.0 store Low rating increases reputation risk signal (+1.0), though rating_count not confirmed >= 50.
- tail_attack_surface anomaly api install_perm_anomaly.tail_attack_surface=true; high-tier permissions on low-install extension.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@1.9.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11023 | jquery@1.9.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@1.9.1 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- storage low Local key-value storage; minimal risk.
- unlimitedStorage low Extends storage quota; low standalone risk.
- proxy high Can reroute all browser traffic through attacker-chosen proxy; critical for VPN but high-risk.
- *://*/* high Broad host access across all sites; paired with proxy amplifies traffic interception risk.
- <all_urls> high Redundant with *://*/* — grants full URL access; combined ×1.2 multiplier applies.
Pillar Scores
Permissions8.00
Reputation7.50
Network4.50
Webstore6.50
Maintenance10.00
Privacy10.00
Code Quality2.00
CVE Exposure3.75
Bookkeeping
Rubric v3.6
Scored at 2026-09-15 12:15
Listing SHA
c9b00c0c6324…
Force block
— not fired
Score recovered
no
Elapsed
—