CRX aminer
Extension icon

Hola VPN - Your Website Unblocker

Version 1.249.511 View in Chrome Web Store

Last scanned: about 4 hours ago

Extension Details

Developer: https://hola.org/
Rating: 4.8 ★ (368K ratings)
Users: 5,000,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

Hola VPN has significant market presence with 5 million users and a high 4.8-star rating from 368,000 reviews, suggesting widespread adoption. However, Hola has a controversial history in the VPN industry, having previously operated a peer-to-peer network model that used users' devices as exit nodes for other users' traffic, raising serious privacy and security concerns. The company has faced criticism for potentially exposing users to legal liability and security risks.

Concerns:

The extension's permission set is extremely invasive and goes beyond what's necessary for basic VPN functionality. The proxy permission combined with webRequest allows complete traffic interception and modification. The broad host permissions grant access to all websites, enabling comprehensive browsing surveillance. The cookies permission allows manipulation of authentication tokens across all sites. The extensive list of content script domains suggests a complex infrastructure that could be used for tracking or data collection beyond VPN services.

Recommendations:

Given the critical risk level, run this extension in a completely isolated Chrome profile with no access to personal accounts or sensitive data. Consider using established VPN providers with better privacy track records instead. If you must use Hola, regularly audit what data is being collected and transmitted. Be aware that free VPN services often monetize user data or bandwidth. Monitor your network traffic for unexpected connections and disable the extension when not actively needed for unblocking content.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: proxy
This extension has the proxy permission. Can control proxy settings. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.