Proton VPN free
pgegfnolipocfakkldnkommjffijfejf
Risk Score
5.39
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- Brand impersonation: claims to be 'Proton VPN' but developer is free-webmail gmail user with no connection to Proton AG.
- proxy permission routes all browser traffic through attacker-controlled echosecure.space infrastructure.
- Install URL hijack opens echosecure.space on install — known exfiltration/tracking pattern.
- Privacy policy is Google's generic policy, not scoped to this extension; admits data collection and 3rd-party sharing.
- No developer name, free-webmail email, no verified publisher — zero accountability.
Evidence
- brand_impersonation store Extension named 'Proton VPN free' but developer is aslikap21@gmail.com with no affiliation to Proton AG.
- install_url_hijack crx onInstalled opens https://echosecure.space/ — third-party domain, not Proton.
- proxy_permission manifest proxy declared; can silently reroute all browser traffic to any server.
- generic_privacy_policy store Privacy URL is myaccount.google.com/privacypolicy — Google's own policy, not scoped to this extension.
- free_webmail_no_devname store Developer email aslikap21@gmail.com, developer_name empty, no verified publisher badge.
- js_external_host crx echosecure.space is the sole external JS host — Russian-hosted domain (country: RU).
- description_language store Description is in Russian; targets Russian-speaking users while impersonating a Swiss privacy brand.
- no_csp manifest content_security_policy is null; csp_present == false despite network-routing capability.
Permissions Breakdown
- proxy high Can redirect all browser traffic through arbitrary proxy servers — full network interception capability.
Pillar Scores
Permissions4.00
Reputation8.50
Network4.00
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 14:06
Listing SHA
6bc3bd33dd07…
Force block
— not fired
Score recovered
no
Elapsed
—