CRX aminer

Starting analysis...

Extension icon

Free VPN Proxy - VPNLY

Version 2.2.0 View in Chrome Web Store

Last scanned: 9 days ago | force re-scan

Extension Details

Developer: vpnly.com
Rating: 4.7 ★ (20K ratings)
Users: 1,000,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension has a substantial user base of 1 million users and maintains a high rating of 4.7 stars from 20,000 reviews, which suggests user satisfaction. However, the developer information is limited to just a domain name (vpnly.com), lacking transparency about the company behind the service. VPN extensions inherently require extensive permissions to function, but the combination of permissions here exceeds typical VPN requirements.

Concerns:

The most concerning aspect is the management permission, which allows this extension to control other extensions - completely unnecessary for VPN functionality. The proxy, webRequest, and broad host permissions are expected for a VPN service, but together they create a powerful surveillance capability. The extension can intercept all web traffic, modify requests, and access all websites you visit. The tabs permission adds another layer of browser control that could be exploited for malicious purposes beyond VPN services.

Recommendations:

Given the critical risk level, install this extension only in a separate Chrome profile dedicated to VPN use. Regularly audit what other extensions are installed when this VPN is active, as it can manage them. Consider using established VPN providers with dedicated desktop applications instead of browser extensions. If you must use this extension, avoid accessing sensitive accounts or conducting financial transactions while it's active. Monitor your browsing behavior for any unexpected changes or redirects.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: management
This extension has the management permission. Can manage other extensions. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: proxy
This extension has the proxy permission. Can control proxy settings. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.