Молния VPN
pnlgcjdpkjbacmgcbaciffijdkpdjmib
Risk Score
4.41
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy URL returns fetch error — policy effectively unavailable; privacy pillar maxes out at 10.
- Proxy permission grants full traffic rerouting capability; critical for a VPN but high-trust if dev is unverified.
- Developer is free-webmail (gmail) with no developer name and no verified publisher status.
- No CSP declared (MV3 provides default but csp_present==false); minor residual risk.
- Small install base (1,000) with high-tier permission and unresolvable privacy policy.
Evidence
- proxy permission declared manifest proxy grants ability to intercept/redirect all browser traffic — critical capability for VPN but high risk if misused.
- privacy policy fetch failed api fetch_error:HTTPError on https://myxavpn.com/privacy/ — policy not accessible; scored as no policy.
- free-webmail developer with no name store Developer email namikkm13@gmail.com; developer_name empty; no verified publisher badge.
- no CSP declared manifest csp_present==false; MV3 defaults apply but explicit CSP absent.
- single external JS host crx js_external_hosts=[myxavpn.com]; matches stated VPN service domain — limited network surface.
- no code findings or obfuscation crx obfuscation_score=0.0; code_findings_raw empty across 4 JS files scanned.
- no CVEs, bad hosts, or monetization hits api cve_findings_raw, bad_host_hits, monetization_hits, affiliate_hits all empty.
- wayback ownership unchanged api wayback_ownership.ownership_changed=false; no sibling extensions in operator cluster.
Permissions Breakdown
- proxy high Full proxy control: can intercept and reroute all browser traffic.
- storage low Local key-value storage; low standalone risk.
Pillar Scores
Permissions4.00
Reputation6.50
Network2.00
Webstore0.00
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 14:20
Listing SHA
2653a6161fc3…
Force block
— not fired
Score recovered
no
Elapsed
—