Is Free VPN Proxy - 1VPN safe?

Medium risk

1VPN is medium risk. On VPN connect, and startup while connected, the extension requests cloudflaircdn.com, resembling Cloudflare's CDN but hardcoded. The server sees your IP/user-agent. Replaced 1vpn.org between v4.1.1/v4.1.3; a GET returned 200 after connect.…

45Risk
Who publishes it

1VPN - no other listings under this identity, 2 shared hostnames

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
1VPN

Shared hosts - 2 hostnames

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

1vpn.org
Also called by 2 other listings, including VPN
cloudflaircdn.com
Also called by 2 other listings, including VPN

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-200
SourceAI SANDBOX

VPN connect and browser startup ping a Cloudflare look-alike domain

On VPN connect, and startup while connected, the extension requests cloudflaircdn.com, resembling Cloudflare's CDN but hardcoded.

The server sees your IP/user-agent.

Replaced 1vpn.org between v4.1.1/v4.1.3; a GET returned 200 after connect.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You connect the VPN, or you open your browser while the VPN is still marked connected.

The extension did this

The extension sends a request to cloudflaircdn.com/proxy_auth/, a domain hardcoded into its code that resembles a Cloudflare CDN.

The request has no body, but the server on the other end sees the connection's source IP address and browser user-agent.

02EvidenceNETWORK CAPTURE
Captured request
GEThttps://cloudflaircdn.com/proxy_auth/
HTTP 200. Captured during dynamic analysis (request ID 1102872.26, source=ext-page) immediately after the popup VPN connect toggle was pressed; chrome.storage.local.isConnected was true and the popup UI showed 'Connected'. No request body is sent; the destination server receives the client's source IP and user-agent from the connection itself.
Headers
Hostcloudflaircdn.com
User-AgentMozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36
03EvidenceCODE COMPARE
The code that does this

How the destination domain is wired in, from the shipping source.

What it actually does
const apiHost   = "1vpn.org";                         // the extension's stated home
const altHosts  = ["1vpn.co", "onevpn.com", "cloudlogcdn.com"];
const authHost  = "cloudflaircdn.com";                 // beacon target, resembles a Cloudflare CDN
const creds     = { username: "a2epfq5ugq0u", /* ... */ };
// Fired when the user connects the VPN.
chrome.proxy.settings.set({
  value: { mode: "pac_script", pacScript: { data: pacScript, mandatory: true } },
  scope: "regular"
}).then(() => {
  // Once the proxy is in place, ping the hardcoded auth host.
  fetch(`https://${authHost}/proxy_auth/`);   // authHost === "cloudflaircdn.com"
});
// Fired on each browser startup.
chrome.runtime.onStartup.addListener(() => {
  init();
  chrome.storage.local.get(["isConnected"], (state) => {
    if (state.isConnected) {
      fetch(`https://${authHost}/proxy_auth/`);  // re-pings cloudflaircdn.com if still connected
    }
  });
});
04EvidenceTHIRD PARTY LIST
Where the beacon goes:
  • cloudflaircdn.com

    Receives the proxy_auth beacon on connect and startup. Resembles Cloudflare's CDN but is hardcoded, not Cloudflare-owned. Introduced between v4.1.1 and v4.1.3.

  • 1vpn.org

    The extension's stated home (manifest homepage_url). In v4.1.1 the equivalent beacon went here / to the stored API host.

05EvidenceARTIFACT
Reproduce it yourself

Run in the service-worker DevTools console for the 1VPN extension. Wraps fetch so any request to cloudflaircdn.com/proxy_auth/ is logged with a timestamp, letting you confirm the beacon fires on connect and on startup without a network proxy.

RequiresChrome with Developer mode enabled
1vpn-beacon-watch.js · js
// 1vpn-beacon-watch.js
// Paste into the 1VPN service-worker DevTools console, then connect the VPN.
(function () {
  const orig = self.fetch.bind(self);
  self.fetch = function (input, init) {
    const url = typeof input === 'string' ? input : (input && input.url) || '';
    if (url.includes('cloudflaircdn.com')) {
      console.log('[1VPN_BEACON]', new Date().toISOString(), url);
    }
    return orig(input, init);
  };
  console.log('[1VPN_BEACON_WATCH] installed. Connect the VPN to see the proxy_auth beacon.');
})();
How to run it
  1. 1
    Open chrome://extensions, enable Developer mode.
  2. 2
    Click the service worker link.
  3. 3
    Paste this script into DevTools console.
  4. 4
    Connect the VPN; watch for [1VPN_BEACON] lines.
  5. 5
    Restart Chrome connected to see the re-ping.
SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

1VPN beacons to cloudflaircdn.com after VPN connection

Connecting Free VPN Proxy - 1VPN applies proxy settings then GETs https://cloudflaircdn.com/proxy_auth/.

Same request fires on startup if stored state says connected.

No body; exposed data is the source IP seen by the host.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You connect the VPN, or start the browser while the VPN is already connected.

The popup toggle calls the connection handler when the stored connection state is off; startup checks the stored connected flag.

The extension did this

The extension sends a GET request to cloudflaircdn.com after the proxy setup step completes.

The reviewed code performs the same request on browser startup when the stored connected flag is true.

02EvidenceFIELD TABLE
Data visible to the destination
FieldValueWhy it matters
Your source IP address
198.51.100.24 (illustrative)Lets the receiving host associate the connection beacon with the network address used by your browser at that moment.
Connection event
VPN connected; browser startup while connectedShows that the request is tied to connecting the VPN or reopening the browser while already connected.
03EvidenceNETWORK CAPTURE
Captured request
GEThttps://cloudflaircdn.com/proxy_auth/
04EvidenceCORRESPONDENCE
Two paths issue the same beacon
WhenYou didExtension did
after proxy settings resolve
user
You switch the VPN from disconnected to connected in the popup.
extension
The extension installs proxy settings and then requests cloudflaircdn.com/proxy_auth/.
during extension startup
user
You start the browser while the extension still has a connected state saved.
extension
The startup listener checks the saved state and requests the same endpoint when it is connected.
05EvidenceCODE COMPARE
The code that does this

Shipped code and deobfuscated code both show the beacon paths

What it actually does
Hardcoded destination in the deobfuscated background bundlebackground.bundle.js
const e = "1vpn.org",
  t = ["1vpn.co", "onevpn.com", "cloudlogcdn.com"],
  o = "cloudflaircdn.com",
  r = (chrome.i18n.getUILanguage(), {
    username: "a2epfq5ugq0u",
    password: "ptkx3fqg6v7n"
  });
Popup connection handler sends the beacon after proxy setuppopup.bundle.js
bn = async () => {
  chrome.storage.local.get(["currentLocation", "locations", "isPremium"], e => {
    if (!e.currentLocation) return;
    const t = (e.locations || gn)[e.currentLocation];
    if (t && t.hosts) {
      {
        chrome.management.getAll(e => {
          e.forEach(e => {
            e.permissions && e.permissions.includes("proxy") && e.id !== chrome.runtime.id && chrome.management.setEnabled(e.id, !1)
          })
        });
        const e = (e => {
          const t = e.reduce((e, t) => e + `HTTPS ${t.hostname}:${t.port};`, "");
          return `
    function FindProxyForURL(url, host) {
      if (${yn.map(e=>`dnsDomainIs(host, "${e}")`).join(" || ")}) {
        return "DIRECT";
      }
      return "${t}";
    }
  `
        })([...t.hosts].sort(() => Math.random() - .5));
        chrome.proxy.settings.set({
          value: {
            mode: "pac_script",
            pacScript: {
              data: e,
              mandatory: !0
            }
          },
          scope: "regular"
        }).then(() => {
          fetch("https://cloudflaircdn.com/proxy_auth/")
        })
      }
      chrome.storage.local.set({
        isConnected: !0
      }), vn()
    }
  })
}
Popup toggle chooses the connection handler when disconnectedpopup.bundle.js
const _ = () => {
  w(!b), b ? wn() : bn()
}
Background startup path repeats the beacon when connectedbackground.bundle.js
chrome.runtime.onStartup.addListener(() => {
  l(), chrome.storage.local.get(["isConnected"], e => {
    e.isConnected && fetch(`https://${o}/proxy_auth/`)
  })
})
06EvidenceTHIRD PARTY LIST
External host contacted by the beacon
  • cloudflaircdn.com

    Receives the proxy_auth GET request after VPN connection and on connected browser startup.

Updated 30 September 2026akcocjjpkmlniicdeemdceeajlmoabhg