CRX aminer
Extension icon

VPNCity - Fast & Unlimited VPN | Unblocker

Version 2.2.2 View in Chrome Web Store

Last scanned: about 6 hours ago

Extension Details

Developer: INVIZBOX LIMITED
Rating: 2.9 ★ (63 ratings)
Users: 40,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension has a concerning trust profile with only 40,000 users and a poor 2.9-star rating from 63 reviews, indicating user dissatisfaction. While INVIZBOX LIMITED appears to be a legitimate VPN company, the low rating suggests potential issues with functionality or user experience. The relatively small user base for a VPN service raises questions about its reliability and market acceptance.

Concerns:

The extension exhibits multiple red flags that justify the critical risk rating. The combination of privacy, proxy, and webRequest permissions creates a powerful toolkit that could intercept, modify, and redirect all web traffic. The broad host permissions and content script injection capabilities mean this extension can access and potentially manipulate data on every website you visit. For a VPN extension, while some of these permissions are functionally necessary, the extensive scope creates significant attack surface if the extension is compromised or malicious.

Recommendations:

Given the critical risk level, avoid installing this extension on your primary browser profile. If you must use it, create a dedicated Chrome profile specifically for VPN usage and avoid accessing sensitive accounts or websites while it's active. Consider well-established VPN providers with better ratings and larger user bases. Monitor your network traffic and browser behavior closely if you choose to proceed. The poor user ratings suggest you may encounter functionality issues beyond security concerns.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: privacy
This extension has the privacy permission. Can modify privacy settings. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: proxy
This extension has the proxy permission. Can control proxy settings. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.