Is Free VPN for Chrome - VPN Proxy 1clickVPN safe?
Free VPN for Chrome sends every URL you visit, along with referrer and timestamps, to the developer's own monitoring server.
A background listener intercepts every HTTP and HTTPS request your browser makes and assembles a payload containing the full target URL, referrer URL, a persistent device ID, timestamp, and response metadata. This payload is posted to astrid.1clickvpn.net via the Sentry error-monitoring service. The collection is on by default and only stops if you explicitly set the vpnDiagnostics flag to zero; the developer applies 20% random sampling server-side, meaning roughly one in five requests is stored.
Who publishes it1clickVPN - no other listings under this identity, 1 shared hostname
1clickVPN - no other listings under this identity, 1 shared hostname
What this publisher told the store about itself, and the other listings that told it the same thing.
Shared hosts - 1 hostname
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Browsing History Sent to Developer via Sentry
Every site you visit is reported to the developer via Sentry, repurposed as a tracking channel.
A listener assembles a record per page load: URL, referrer, an account-tied ID, foreground status, sent server-side, until diagnostics are off.
You open a new tab and navigate to any website.
No special interaction is required; this fires on every completed main-frame page load.
The extension captures the URL, referrer, your user ID, and tab state, then posts them to the developer's server.
The request is sent as a Sentry 'envelope' to astrid.1clickvpn.net/44, a private server controlled by the 1clickvpn team.
| User-Agent | sentry.javascript.browser/7.120.3 |
| Content-Type | application/x-sentry-envelope |
{"sent_at":"2026-03-26T16:16:37.000Z"}
{"type":"event"}
{"message":"onCompletedListener","level":"info","contexts":{"req":{"targetUrl":"https://www.google.com/","referrerUrl":"","requestType":"main_frame","contentType":"text/html; charset=UTF-8","statusCode":200,"foreground":true,"deviceTimestamp":1743005797412,"fileDate":"2026-03-26T16:16:37.412Z","userId":"81529c1b-1515-4ecf-9b4f-10739be4dbcd"}},"user":{"id":"81529c1b-1515-4ecf-9b4f-10739be4dbcd"}}| Field | Value | Why it matters | |
|---|---|---|---|
Page you visited | https://www.google.com/search?q=symptoms+of+depression | The full URL of every website you load is sent to the developer. | |
Referring page | https://mail.google.com/mail/u/0/#inbox | The page you came from, revealing your navigation path. | |
Your account ID | 81529c1b-1515-4ecf-9b4f-10739be4dbcd | A unique identifier tied to your extension install, allowing all your visits to be linked together forever. | |
Timestamp | 1743005797412 (2026-03-26T16:16:37.412Z) | Exact millisecond time of the request, enabling reconstruction of your browsing timeline. | |
Tab visibility | true | Whether the tab was in the foreground, helping the developer know which sites you were actively reading. | |
Content type | text/html; charset=UTF-8 | The type of content the server returned (e.g. HTML page, JSON API response). |
The tracking listener, shipped vs. readable
// Registers for ALL http and https traffic — every site you visit
chrome.webRequest.onCompleted.addListener(
this.onCompletedListener,
{ urls: ['http://*/*', 'https://*/*'] },
['responseHeaders', 'extraHeaders']
);// Assembles the surveillance payload for each completed page load
const payload = {
fileDate: new Date().toISOString(), // ISO timestamp
deviceTimestamp: Date.now(), // Unix ms
userId: this.storage.id, // stable UUID from chrome.storage
referrerUrl: referrer, // page you came from
targetUrl: url, // page you visited
requestType: type, // always 'main_frame'
contentType: contentType || null, // e.g. 'text/html'
statusCode: statusCode, // HTTP status
foreground: await this.checkForeground(tabId) // was tab active?
};
this.sendRequest(payload, 'onCompletedListener');async sendRequest(data, messageName) {
// Reads vpnDiagnostics from storage.
// UNDEFINED (the default, never set) is treated as ENABLED.
// Only explicitly setting it to 0 disables tracking.
const { vpnDiagnostics } = await chrome.storage.local.get('vpnDiagnostics');
if (vpnDiagnostics !== undefined && +vpnDiagnostics !== 1) {
return; // user opted out
}
// Posts data to developer-controlled Sentry instance
sentryClient.setContext('req', data);
sentryClient.captureMessage(messageName); // triggers POST to astrid.1clickvpn.net/44
}Sentry is a well-known, legitimate crash reporting and observability platform. Developers normally send stack traces and error events to it — not browsing history. By routing surveillance data through Sentry's client SDK and hosting a self-managed Sentry instance at `astrid.1clickvpn.net`, 1clickvpn avoids creating an obvious custom tracking endpoint that security tools would flag. The traffic looks like error reporting and the destination is operated by the developer, so no third party sees the data — but neither does the user.
Sentry's `captureMessage()` API is designed to send arbitrary structured context. The extension uses `setContext('req', payload)` immediately before calling `captureMessage('onCompletedListener')`, which packages the full browsing record into the Sentry envelope body.
- astrid.1clickvpn.net
Developer-run self-hosted Sentry instance. Receives browsing-history payloads via the Sentry envelope API. Owned by 1clickvpn; no third-party sharing, no visibility into retention.
Install-time IP geolocation lookup to third-party sweb.ru
On install, the service worker fetches your public IP from sweb.ru, then POSTs it back to resolve a country code. sweb.ru is a Russian host unrelated to 1clickvpn.net, undescribed in the listing.
Both fired in the first second, HTTP 200.
You install the extension.
The geolocation lookup runs automatically before any onboarding step.
The service worker fetches your IP from sweb.ru and asks sweb.ru to resolve it to a country code.
sweb.ru is a Russian hosting provider unrelated to the publisher 1clickvpn.net.
The install handler resolves the user's country via two sweb.ru requests.
async function getInstallUninstallLinks() {
let ip = (await fetch('https://sweb.ru/geoip/getIp_ajax')
.then(r => r.json()))?.js?.ip;
if (!ip) return { install: defaultUrl, ru: false };
let isRu = (await fetch('https://sweb.ru/geoip/getData_ajax', {
method: 'POST',
headers: { 'content-type': 'application/x-www-form-urlencoded' },
body: `ip=${ip}`
}).then(r => r.json()))?.js?.data?.countryCode === 'RU';
return { install: isRu ? chrome.runtime.getURL('vpn.html') : defaultUrl, ru: isRu };
}| content-type | application/x-www-form-urlencoded |
ip=<your public IP>
- sweb.ru
Russian hosting provider (SpaceWeb) unrelated to the publisher; receives your public IP and returns a country code used to branch onboarding and the uninstall URL.
Russian users redirected on install to a bundled AltaVPN promo page
An install-time geolocation check sends Russia-resolved users to a bundled Russian page (vpn.html), not 1clickvpn.net/download-vpn.
It redirects to altavpn.net and Telegram bot t.me/altavpn_bot.
Confirmed by dynamic analysis.
You install the extension from a Russian IP address.
The country is decided by the install-time sweb.ru geolocation lookup.
The extension opens a bundled Russian-language page promoting a different VPN service instead of the normal onboarding page.
Non-Russian users are taken to 1clickvpn.net/download-vpn instead.
When the country code is RU, the install URL becomes the bundled vpn.html.
let isRu = (... sweb.ru getData_ajax ...)?.js?.data?.countryCode === 'RU';
return {
install: isRu ? chrome.runtime.getURL('vpn.html') // Russian users
: `${PUBLIC_DOMAIN}/download-vpn`, // everyone else
ru: isRu
};
// ... in onInstalled:
let e = await getInstallUninstallLinks();
chrome.tabs.create({ url: e.install, active: true });| Field | Value | Why it matters | |
|---|---|---|---|
Page title | 1clickVPN – Подключиться через AltaVPN | The bundled page is branded as redirecting the user to AltaVPN. | |
Region message | ...ограничено в вашем регионе. | Russian-language text telling the user VPN via this extension is restricted in their region. | |
Promoted website | altavpn.net | A link sending the user to a separate VPN service. | |
Promoted Telegram bot | t.me/altavpn_bot | A Telegram bot link for the third-party service. |
Dynamic analysis confirmed the install-time geolocation code path runs (the sweb.ru lookups fired on install). The redirect to vpn.html is gated on a Russian country result, so it was not triggered from the non-Russian analysis IP; the conditional redirect code and the bundled Russian-language vpn.html page are both present in the shipped extension.
+4 more findings not shown
Where it sends data
Destinations our analysis observed 1clickVPN contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- astrid.1clickvpn.net
1clickVPN sends data to astrid.1clickvpn.net. No other extension we have analysed sends data here.