Is Free VPN Proxy - 1VPN safe?
1VPN is medium risk. On VPN connect, and startup while connected, the extension requests cloudflaircdn.com, resembling Cloudflare's CDN but hardcoded. The server sees your IP/user-agent. Replaced 1vpn.org between v4.1.1/v4.1.3; a GET returned 200 after connect.…
Who publishes it1VPN - no other listings under this identity, 2 shared hostnames
1VPN - no other listings under this identity, 2 shared hostnames
What this publisher told the store about itself, and the other listings that told it the same thing.
Shared hosts - 2 hostnames
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
VPN connect and browser startup ping a Cloudflare look-alike domain
On VPN connect, and startup while connected, the extension requests cloudflaircdn.com, resembling Cloudflare's CDN but hardcoded.
The server sees your IP/user-agent.
Replaced 1vpn.org between v4.1.1/v4.1.3; a GET returned 200 after connect.
You connect the VPN, or you open your browser while the VPN is still marked connected.
The extension sends a request to cloudflaircdn.com/proxy_auth/, a domain hardcoded into its code that resembles a Cloudflare CDN.
The request has no body, but the server on the other end sees the connection's source IP address and browser user-agent.
| Host | cloudflaircdn.com |
| User-Agent | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36 |
How the destination domain is wired in, from the shipping source.
const apiHost = "1vpn.org"; // the extension's stated home
const altHosts = ["1vpn.co", "onevpn.com", "cloudlogcdn.com"];
const authHost = "cloudflaircdn.com"; // beacon target, resembles a Cloudflare CDN
const creds = { username: "a2epfq5ugq0u", /* ... */ };// Fired when the user connects the VPN.
chrome.proxy.settings.set({
value: { mode: "pac_script", pacScript: { data: pacScript, mandatory: true } },
scope: "regular"
}).then(() => {
// Once the proxy is in place, ping the hardcoded auth host.
fetch(`https://${authHost}/proxy_auth/`); // authHost === "cloudflaircdn.com"
});// Fired on each browser startup.
chrome.runtime.onStartup.addListener(() => {
init();
chrome.storage.local.get(["isConnected"], (state) => {
if (state.isConnected) {
fetch(`https://${authHost}/proxy_auth/`); // re-pings cloudflaircdn.com if still connected
}
});
});- cloudflaircdn.com
Receives the proxy_auth beacon on connect and startup. Resembles Cloudflare's CDN but is hardcoded, not Cloudflare-owned. Introduced between v4.1.1 and v4.1.3.
- 1vpn.org
The extension's stated home (manifest homepage_url). In v4.1.1 the equivalent beacon went here / to the stored API host.
Run in the service-worker DevTools console for the 1VPN extension. Wraps fetch so any request to cloudflaircdn.com/proxy_auth/ is logged with a timestamp, letting you confirm the beacon fires on connect and on startup without a network proxy.
// 1vpn-beacon-watch.js
// Paste into the 1VPN service-worker DevTools console, then connect the VPN.
(function () {
const orig = self.fetch.bind(self);
self.fetch = function (input, init) {
const url = typeof input === 'string' ? input : (input && input.url) || '';
if (url.includes('cloudflaircdn.com')) {
console.log('[1VPN_BEACON]', new Date().toISOString(), url);
}
return orig(input, init);
};
console.log('[1VPN_BEACON_WATCH] installed. Connect the VPN to see the proxy_auth beacon.');
})();
- 1Open chrome://extensions, enable Developer mode.
- 2Click the service worker link.
- 3Paste this script into DevTools console.
- 4Connect the VPN; watch for [1VPN_BEACON] lines.
- 5Restart Chrome connected to see the re-ping.
1VPN beacons to cloudflaircdn.com after VPN connection
Connecting Free VPN Proxy - 1VPN applies proxy settings then GETs https://cloudflaircdn.com/proxy_auth/.
Same request fires on startup if stored state says connected.
No body; exposed data is the source IP seen by the host.
You connect the VPN, or start the browser while the VPN is already connected.
The popup toggle calls the connection handler when the stored connection state is off; startup checks the stored connected flag.
The extension sends a GET request to cloudflaircdn.com after the proxy setup step completes.
The reviewed code performs the same request on browser startup when the stored connected flag is true.
| Field | Value | Why it matters | |
|---|---|---|---|
Your source IP address | 198.51.100.24 (illustrative) | Lets the receiving host associate the connection beacon with the network address used by your browser at that moment. | |
Connection event | VPN connected; browser startup while connected | Shows that the request is tied to connecting the VPN or reopening the browser while already connected. |
| When | You did | Extension did |
|---|---|---|
| after proxy settings resolve | user You switch the VPN from disconnected to connected in the popup. | extension The extension installs proxy settings and then requests cloudflaircdn.com/proxy_auth/. |
| during extension startup | user You start the browser while the extension still has a connected state saved. | extension The startup listener checks the saved state and requests the same endpoint when it is connected. |
Shipped code and deobfuscated code both show the beacon paths
const e = "1vpn.org",
t = ["1vpn.co", "onevpn.com", "cloudlogcdn.com"],
o = "cloudflaircdn.com",
r = (chrome.i18n.getUILanguage(), {
username: "a2epfq5ugq0u",
password: "ptkx3fqg6v7n"
});bn = async () => {
chrome.storage.local.get(["currentLocation", "locations", "isPremium"], e => {
if (!e.currentLocation) return;
const t = (e.locations || gn)[e.currentLocation];
if (t && t.hosts) {
{
chrome.management.getAll(e => {
e.forEach(e => {
e.permissions && e.permissions.includes("proxy") && e.id !== chrome.runtime.id && chrome.management.setEnabled(e.id, !1)
})
});
const e = (e => {
const t = e.reduce((e, t) => e + `HTTPS ${t.hostname}:${t.port};`, "");
return `
function FindProxyForURL(url, host) {
if (${yn.map(e=>`dnsDomainIs(host, "${e}")`).join(" || ")}) {
return "DIRECT";
}
return "${t}";
}
`
})([...t.hosts].sort(() => Math.random() - .5));
chrome.proxy.settings.set({
value: {
mode: "pac_script",
pacScript: {
data: e,
mandatory: !0
}
},
scope: "regular"
}).then(() => {
fetch("https://cloudflaircdn.com/proxy_auth/")
})
}
chrome.storage.local.set({
isConnected: !0
}), vn()
}
})
}const _ = () => {
w(!b), b ? wn() : bn()
}chrome.runtime.onStartup.addListener(() => {
l(), chrome.storage.local.get(["isConnected"], e => {
e.isConnected && fetch(`https://${o}/proxy_auth/`)
})
})- cloudflaircdn.com
Receives the proxy_auth GET request after VPN connection and on connected browser startup.