1ClickVPN Proxy for Chrome
pphgdbgldlmicfdkhondlafkiomnelnk
Risk Score
4.52
Risk Level:
Medium
Recommendation:
🚫 BLOCK
FORCE-BLOCK
Top Risks
- FORCE BLOCK: management + broad host access — extension can disable security tools AND has full traffic-routing capability.
- proxy + <all_urls> + webRequest: can silently reroute and inspect all browser traffic.
- management permission allows disabling/uninstalling other extensions.
- No CSP declared (MV3 strict default applies, but new Function() in 3 files is concerning).
- External hosts include tinyurl.com, facebook.com, tiktok.com beyond core VPN function.
Evidence
- proxy+webRequest+<all_urls> manifest Full traffic interception capability; justified for VPN but very high impact if compromised.
- management permission manifest Can control other installed extensions; unusual and high-risk for a VPN.
- function_constructor x3 crx new Function() in anti-malware.js, content.js, service_worker.js — dynamic code execution risk.
- external hosts crx tinyurl.com, www.facebook.com, www.tiktok.com contacted; not typical for a pure VPN function.
- no_csp manifest content_security_policy is null; MV3 default applies but new Function() findings still present.
- featured_by_google store Google Featured badge provides partial trust signal; not a verified publisher badge.
- privacy_policy store Scoped policy with data collection, retention, and third-party sharing disclosed — adequate.
- no_bad_hosts_no_cves api threat_intel shows no bad-host hits, no CVEs, no monetization or affiliate hits.
Permissions Breakdown
- webRequest high Can observe and intercept all network requests across all sites.
- proxy high Can reroute all browser traffic through attacker-controlled servers.
- management high Can list, disable, or uninstall other extensions.
- <all_urls> high Broad host access across every site; amplifies proxy/webRequest risk.
- tabs medium Can read tab URLs and titles across all sites.
- scripting medium Can inject scripts into any page under <all_urls>.
- webNavigation medium Can observe full navigation history and patterns.
- webRequestAuthProvider medium Can supply credentials for proxy authentication challenges.
- storage low Local data storage; low standalone risk.
- alarms low Scheduling only; no direct data access.
- offscreen low Off-screen document; low risk without DOM exfil evidence.
- https://*.bugsnag.com/* low Scoped to crash reporting service domain.
Pillar Scores
Permissions7.50
Reputation4.00
Network3.50
Webstore2.00
Maintenance0.00
Privacy1.00
Code Quality2.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 04:24
Listing SHA
b929bbf70525…
Force block
🚫 fired
Score recovered
no
Elapsed
—