Is Free VPN for Chrome - VPN Proxy 1clickVPN safe?

High risk

Free VPN for Chrome sends every URL you visit, along with referrer and timestamps, to the developer's own monitoring server.

A background listener intercepts every HTTP and HTTPS request your browser makes and assembles a payload containing the full target URL, referrer URL, a persistent device ID, timestamp, and response metadata. This payload is posted to astrid.1clickvpn.net via the Sentry error-monitoring service. The collection is on by default and only stops if you explicitly set the vpnDiagnostics flag to zero; the developer applies 20% random sampling server-side, meaning roughly one in five requests is stored.

1clickVPNv2.0.25Chrome Web Store
75Risk
Who publishes it

1clickVPN - no other listings under this identity, 1 shared hostname

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
1clickVPN

Shared hosts - 1 hostname

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

1clickvpn.net
Also called by 2 other listings, including Ускорить Ютуб | Обойти замедление

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-200
SourceAI SANDBOX

Browsing History Sent to Developer via Sentry

Every site you visit is reported to the developer via Sentry, repurposed as a tracking channel.

A listener assembles a record per page load: URL, referrer, an account-tied ID, foreground status, sent server-side, until diagnostics are off.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You open a new tab and navigate to any website.

No special interaction is required; this fires on every completed main-frame page load.

The extension did this

The extension captures the URL, referrer, your user ID, and tab state, then posts them to the developer's server.

The request is sent as a Sentry 'envelope' to astrid.1clickvpn.net/44, a private server controlled by the 1clickvpn team.

02EvidenceNETWORK CAPTURE
Captured request
POSThttps://astrid.1clickvpn.net/api/44/envelope/
200 OK, confirmed receipt by developer Sentry instance
Headers
User-Agentsentry.javascript.browser/7.120.3
Content-Typeapplication/x-sentry-envelope
Body
{"sent_at":"2026-03-26T16:16:37.000Z"}
{"type":"event"}
{"message":"onCompletedListener","level":"info","contexts":{"req":{"targetUrl":"https://www.google.com/","referrerUrl":"","requestType":"main_frame","contentType":"text/html; charset=UTF-8","statusCode":200,"foreground":true,"deviceTimestamp":1743005797412,"fileDate":"2026-03-26T16:16:37.412Z","userId":"81529c1b-1515-4ecf-9b4f-10739be4dbcd"}},"user":{"id":"81529c1b-1515-4ecf-9b4f-10739be4dbcd"}}
03EvidenceFIELD TABLE
Data sent with each page visit
FieldValueWhy it matters
Page you visited
https://www.google.com/search?q=symptoms+of+depressionThe full URL of every website you load is sent to the developer.
Referring page
https://mail.google.com/mail/u/0/#inboxThe page you came from, revealing your navigation path.
Your account ID
81529c1b-1515-4ecf-9b4f-10739be4dbcdA unique identifier tied to your extension install, allowing all your visits to be linked together forever.
Timestamp
1743005797412 (2026-03-26T16:16:37.412Z)Exact millisecond time of the request, enabling reconstruction of your browsing timeline.
Tab visibility
trueWhether the tab was in the foreground, helping the developer know which sites you were actively reading.
Content type
text/html; charset=UTF-8The type of content the server returned (e.g. HTML page, JSON API response).
04EvidenceCODE COMPARE
The code that does this

The tracking listener, shipped vs. readable

What it actually does
webRequest listener registration (all URLs)
// Registers for ALL http and https traffic — every site you visit
chrome.webRequest.onCompleted.addListener(
  this.onCompletedListener,
  { urls: ['http://*/*', 'https://*/*'] },
  ['responseHeaders', 'extraHeaders']
);
Payload assembly inside onCompleted handler
// Assembles the surveillance payload for each completed page load
const payload = {
  fileDate: new Date().toISOString(),     // ISO timestamp
  deviceTimestamp: Date.now(),            // Unix ms
  userId: this.storage.id,                // stable UUID from chrome.storage
  referrerUrl: referrer,                  // page you came from
  targetUrl: url,                         // page you visited
  requestType: type,                      // always 'main_frame'
  contentType: contentType || null,       // e.g. 'text/html'
  statusCode: statusCode,                 // HTTP status
  foreground: await this.checkForeground(tabId)  // was tab active?
};
this.sendRequest(payload, 'onCompletedListener');
sendRequest: opt-out guard + Sentry dispatch
async sendRequest(data, messageName) {
  // Reads vpnDiagnostics from storage.
  // UNDEFINED (the default, never set) is treated as ENABLED.
  // Only explicitly setting it to 0 disables tracking.
  const { vpnDiagnostics } = await chrome.storage.local.get('vpnDiagnostics');
  if (vpnDiagnostics !== undefined && +vpnDiagnostics !== 1) {
    return; // user opted out
  }
  // Posts data to developer-controlled Sentry instance
  sentryClient.setContext('req', data);
  sentryClient.captureMessage(messageName); // triggers POST to astrid.1clickvpn.net/44
}
05EvidencePLAIN NOTE
Why Sentry?

Sentry is a well-known, legitimate crash reporting and observability platform. Developers normally send stack traces and error events to it — not browsing history. By routing surveillance data through Sentry's client SDK and hosting a self-managed Sentry instance at `astrid.1clickvpn.net`, 1clickvpn avoids creating an obvious custom tracking endpoint that security tools would flag. The traffic looks like error reporting and the destination is operated by the developer, so no third party sees the data — but neither does the user.

Sentry's `captureMessage()` API is designed to send arbitrary structured context. The extension uses `setContext('req', payload)` immediately before calling `captureMessage('onCompletedListener')`, which packages the full browsing record into the Sentry envelope body.

06EvidenceTHIRD PARTY LIST
Where your browsing data goes
  • astrid.1clickvpn.net

    Developer-run self-hosted Sentry instance. Receives browsing-history payloads via the Sentry envelope API. Owned by 1clickvpn; no third-party sharing, no visibility into retention.

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-200
SourceAI SANDBOX

Install-time IP geolocation lookup to third-party sweb.ru

On install, the service worker fetches your public IP from sweb.ru, then POSTs it back to resolve a country code. sweb.ru is a Russian host unrelated to 1clickvpn.net, undescribed in the listing.

Both fired in the first second, HTTP 200.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You install the extension.

The geolocation lookup runs automatically before any onboarding step.

The extension did this

The service worker fetches your IP from sweb.ru and asks sweb.ru to resolve it to a country code.

sweb.ru is a Russian hosting provider unrelated to the publisher 1clickvpn.net.

02EvidenceCODE COMPARE
The code that does this

The install handler resolves the user's country via two sweb.ru requests.

What it actually does
async function getInstallUninstallLinks() {
  let ip = (await fetch('https://sweb.ru/geoip/getIp_ajax')
              .then(r => r.json()))?.js?.ip;
  if (!ip) return { install: defaultUrl, ru: false };
  let isRu = (await fetch('https://sweb.ru/geoip/getData_ajax', {
    method: 'POST',
    headers: { 'content-type': 'application/x-www-form-urlencoded' },
    body: `ip=${ip}`
  }).then(r => r.json()))?.js?.data?.countryCode === 'RU';
  return { install: isRu ? chrome.runtime.getURL('vpn.html') : defaultUrl, ru: isRu };
}
03EvidenceNETWORK CAPTURE
Captured request
POSThttps://sweb.ru/geoip/getData_ajax
Observed during dynamic analysis: a GET to sweb.ru/geoip/getIp_ajax fired in the first second of a fresh install (HTTP 200), immediately followed by this POST carrying the resolved IP (HTTP 200). Both fired from the background service worker before any user interaction or terms acceptance.
Headers
content-typeapplication/x-www-form-urlencoded
Body
ip=<your public IP>
04EvidenceTHIRD PARTY LIST
Where your IP and country are resolved
  • sweb.ru

    Russian hosting provider (SpaceWeb) unrelated to the publisher; receives your public IP and returns a country code used to branch onboarding and the uninstall URL.

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-829
SourceAI SANDBOX

Russian users redirected on install to a bundled AltaVPN promo page

An install-time geolocation check sends Russia-resolved users to a bundled Russian page (vpn.html), not 1clickvpn.net/download-vpn.

It redirects to altavpn.net and Telegram bot t.me/altavpn_bot.

Confirmed by dynamic analysis.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You install the extension from a Russian IP address.

The country is decided by the install-time sweb.ru geolocation lookup.

The extension did this

The extension opens a bundled Russian-language page promoting a different VPN service instead of the normal onboarding page.

Non-Russian users are taken to 1clickvpn.net/download-vpn instead.

02EvidenceCODE COMPARE
The code that does this

When the country code is RU, the install URL becomes the bundled vpn.html.

What it actually does
let isRu = (... sweb.ru getData_ajax ...)?.js?.data?.countryCode === 'RU';
return {
  install: isRu ? chrome.runtime.getURL('vpn.html')   // Russian users
                : `${PUBLIC_DOMAIN}/download-vpn`,      // everyone else
  ru: isRu
};
// ... in onInstalled:
let e = await getInstallUninstallLinks();
chrome.tabs.create({ url: e.install, active: true });
03EvidenceFIELD TABLE
What the bundled vpn.html page contains
FieldValueWhy it matters
Page title
1clickVPN – Подключиться через AltaVPNThe bundled page is branded as redirecting the user to AltaVPN.
Region message
...ограничено в вашем регионе.Russian-language text telling the user VPN via this extension is restricted in their region.
Promoted website
altavpn.netA link sending the user to a separate VPN service.
Promoted Telegram bot
t.me/altavpn_botA Telegram bot link for the third-party service.
04EvidencePLAIN NOTE
What was and wasn't directly observed

Dynamic analysis confirmed the install-time geolocation code path runs (the sweb.ru lookups fired on install). The redirect to vpn.html is gated on a Russian country result, so it was not triggered from the non-Russian analysis IP; the conditional redirect code and the bundled Russian-language vpn.html page are both present in the shipped extension.

+4 more findings not shown

Where it sends data

Destinations our analysis observed 1clickVPN contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • astrid.1clickvpn.net

    1clickVPN sends data to astrid.1clickvpn.net. No other extension we have analysed sends data here.

Updated 30 September 2026fcfhplploccackoneaefokcmbjfbkenj