android VPN
pddhejgmgakilndagfaffgochjojogfp
Risk Score
4.32
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- proxy permission routes all browser traffic through echosecure.space, a single unverified Russian-hosted domain controlled by an anonymous Gmail developer.
- Privacy policy is Google's own generic policy — not scoped to this extension; data collection/sharing terms are meaningless for this extension.
- Developer is anonymous (no name, free Gmail, no business domain) with 91 installs and high-capability permission — classic tail-attack-surface.
- install_url_hijack: onInstall opens echosecure.space, funneling users to the proxy operator's site immediately after install.
- No CSP on an MV3 extension with proxy capability and an external JS host (echosecure.space) — no script-injection guardrails.
Evidence
- proxy_permission manifest Permission 'proxy' declared — can intercept and redirect all browser HTTP/HTTPS traffic.
- install_url_hijack crx install_url_target=https://echosecure.space/ — onInstalled opens operator site, monetization/tracking risk.
- free_webmail_no_dev_name store Developer email aslikap21@gmail.com, no developer name — anonymous high-capability publisher.
- generic_google_privacy_policy store Privacy URL is Google's own account policy (scope_extension=false, data_collection=true, third_party_sharing=true).
- single_geo_russia api All JS external hosts resolve in RU — echosecure.space hosted in Russia.
- small_install_high_perm api Only 91 installs with high-tier proxy permission — tail-attack-surface anomaly flagged.
- no_csp manifest content_security_policy is null; no script-src restrictions despite external JS host.
- external_js_host crx js_external_hosts=['echosecure.space'] — extension contacts unverified operator domain.
Permissions Breakdown
- proxy high Can reroute all browser traffic through attacker-controlled servers; full network interception capability.
- https://echosecure.space/* medium Narrow host permission to a single unverified domain hosting the proxy backend.
Pillar Scores
Permissions7.00
Reputation8.00
Network4.00
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 14:05
Listing SHA
d76091accc57…
Force block
— not fired
Score recovered
no
Elapsed
—