Urban VPN
nllfmbmeibkjhdidkhnnpbblneepaonh
Risk Score
5.60
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- proxy permission allows full traffic interception/rerouting with no host restrictions
- Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection + 3rd-party sharing
- install_url_hijack: extension opens a third-party URL on install (install_url_target unknown)
- External JS hosts include app.getmyxa.com and t.me — non-VPN-infrastructure domains with geo in NL/RU
- No developer identity: no name, no email, no verified publisher; Cyrillic description inconsistent with claimed product
Evidence
- proxy_permission manifest Single HIGH permission 'proxy' declared; enables full browser traffic redirection.
- install_url_hijack crx install_url_hijack=true; extension opens external URL on install — target unknown.
- generic_google_privacy_policy store Privacy policy is Google's own account policy (myaccount.google.com); scope_extension=false, data_collection=true, third_party_sharing=true.
- external_hosts_non_vpn crx js_external_hosts: app.getmyxa.com (NL) and t.me (RU) — neither is a standard VPN infrastructure domain.
- no_developer_identity store developer_name, developer_email all empty; verified_publisher=false; no featured badge.
- maintenance_unknown api months_since_update=null; last_updated missing; scored conservatively at 6-12mo band.
- host_geo_diversity crx JS hosted across NL and RU — 2 countries; moderate geo-diversity flag for a VPN tool.
- no_csp manifest content_security_policy=null; MV3 default CSP applies but no explicit policy declared.
Permissions Breakdown
- proxy high Allows full traffic rerouting; can intercept/redirect all browser network traffic.
Pillar Scores
Permissions5.50
Reputation7.50
Network3.50
Webstore3.50
Maintenance5.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 14:11
Listing SHA
c582d075cdad…
Force block
— not fired
Score recovered
no
Elapsed
—