Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Salut VPN – Secure Proxy Access

ninkfblhapgjffbmpmimemjicdghkdgg
Risk Score
5.08
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VPN
Installs 1,000
Rating 4.8
Last updated 2026-03-02 (6 months ago)
Manifest version MV3
CSP present ❌ no
Developer silviaferr79@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission routes ALL browser traffic through developer-controlled servers with no accountability.
  • Privacy policy URL returns fetch error; policy effectively non-existent and unverifiable.
  • Gmail developer email with no developer name and no verified publisher badge.
  • External JS host myxavpn.com is the same domain as the inaccessible privacy policy — single unverified operator controls both.
  • VPN/proxy tunneling all traffic via unknown infrastructure in Finland with no transparency on data handling.

Evidence

  • proxy_permission manifest proxy declared — redirects all browser network traffic through extension-controlled endpoints.
  • privacy_policy_fetch_failed api https://myxavpn.com/privacy/ returned HTTPError; policy content unverifiable, scored as not fetched.
  • free_webmail_developer store Developer email silviaferr79@gmail.com is Gmail; no developer name listed; no verified publisher.
  • external_js_host crx js_external_hosts: [myxavpn.com] — same domain as privacy policy; single unverified operator.
  • no_csp manifest content_security_policy is null; MV3 applies default CSP so no v2 network penalty, but no explicit policy.
  • geo_diversity_low api Single JS host country: FI (Finland). No geo-diversity penalty triggered (count=1).
  • maintenance_3_6mo store months_since_update=6; falls in 3-6 month band (+1.5).
  • no_code_findings crx code_findings_raw empty, obfuscation_score=0.0; code quality pillar = 0.

Permissions Breakdown

  • proxy high Routes all browser traffic through attacker-controlled servers; core VPN function but highest-impact permission.
  • storage low Local data persistence for settings; low standalone risk.

Pillar Scores

Permissions6.00
Reputation7.50
Network2.00
Webstore1.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 14:14
Listing SHA 9684c514995b…
Force block — not fired
Score recovered no
Elapsed