VPN Lagless
pplibppgnmomfcnoclechnebccniooai
Risk Score
5.55
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- proxy permission routes ALL browser traffic through attacker-controlled servers (app.myxavpn.pro, routekeeper.space)
- Privacy policy is Google's generic account policy — does not scope data collection to this extension at all
- Free-webmail dev (jomcna56@gmail.com), no developer name, no verifiable business identity
- JS hosts span 4 countries (CA, NL, RU, US) including routekeeper.space — unknown provenance
- No CSP + MV3 with proxy permission and external hosts including t.me (Telegram) — unusual for VPN
Evidence
- proxy_permission manifest proxy declared — enables full browser traffic interception/redirection to arbitrary servers.
- free_webmail_dev_no_name store Developer email jomcna56@gmail.com, no developer name provided, no verifiable business entity.
- generic_google_privacy_policy store Privacy policy points to myaccount.google.com — Google's own policy, not scoped to this extension.
- external_hosts_geo_diversity crx JS contacts app.myxavpn.pro, routekeeper.space, t.me, cloudflare-dns.com, dns.google across CA/NL/RU/US.
- no_csp manifest content_security_policy is null; csp_present==false on MV3 extension with external network endpoints.
- unverified_publisher store verified_publisher=false, is_featured_by_google=false, rating=0, install_count unknown.
- routekeeper_space_unknown_host crx routekeeper.space is an unrecognized host; combined with proxy permission, could redirect all traffic.
- telegram_host crx t.me (Telegram) listed as external JS host — atypical for VPN, potential C2 or exfil channel.
Permissions Breakdown
- proxy high Allows full control over all browser network traffic routing — core VPN risk, highest impact.
Pillar Scores
Permissions7.00
Reputation8.50
Network5.50
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 14:06
Listing SHA
d1b423d662bd…
Force block
— not fired
Score recovered
no
Elapsed
—