Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

1ClickVPN Proxy for Chrome

pphgdbgldlmicfdkhondlafkiomnelnk
Risk Score
4.52
Risk Level: Medium
Recommendation: 🚫 BLOCK FORCE-BLOCK
Category VPN
Installs 400,000
Rating 4.6
Last updated 2026-08-26
Manifest version MV3
CSP present ❌ no
Developer developer@1clickvpn.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • FORCE BLOCK: management + broad host access — extension can disable security tools AND has full traffic-routing capability.
  • proxy + <all_urls> + webRequest: can silently reroute and inspect all browser traffic.
  • management permission allows disabling/uninstalling other extensions.
  • No CSP declared (MV3 strict default applies, but new Function() in 3 files is concerning).
  • External hosts include tinyurl.com, facebook.com, tiktok.com beyond core VPN function.

Evidence

  • proxy+webRequest+<all_urls> manifest Full traffic interception capability; justified for VPN but very high impact if compromised.
  • management permission manifest Can control other installed extensions; unusual and high-risk for a VPN.
  • function_constructor x3 crx new Function() in anti-malware.js, content.js, service_worker.js — dynamic code execution risk.
  • external hosts crx tinyurl.com, www.facebook.com, www.tiktok.com contacted; not typical for a pure VPN function.
  • no_csp manifest content_security_policy is null; MV3 default applies but new Function() findings still present.
  • featured_by_google store Google Featured badge provides partial trust signal; not a verified publisher badge.
  • privacy_policy store Scoped policy with data collection, retention, and third-party sharing disclosed — adequate.
  • no_bad_hosts_no_cves api threat_intel shows no bad-host hits, no CVEs, no monetization or affiliate hits.

Permissions Breakdown

  • webRequest high Can observe and intercept all network requests across all sites.
  • proxy high Can reroute all browser traffic through attacker-controlled servers.
  • management high Can list, disable, or uninstall other extensions.
  • <all_urls> high Broad host access across every site; amplifies proxy/webRequest risk.
  • tabs medium Can read tab URLs and titles across all sites.
  • scripting medium Can inject scripts into any page under <all_urls>.
  • webNavigation medium Can observe full navigation history and patterns.
  • webRequestAuthProvider medium Can supply credentials for proxy authentication challenges.
  • storage low Local data storage; low standalone risk.
  • alarms low Scheduling only; no direct data access.
  • offscreen low Off-screen document; low risk without DOM exfil evidence.
  • https://*.bugsnag.com/* low Scoped to crash reporting service domain.

Pillar Scores

Permissions7.50
Reputation4.00
Network3.50
Webstore2.00
Maintenance0.00
Privacy1.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 04:24
Listing SHA b929bbf70525…
Force block 🚫 fired
Score recovered no
Elapsed