| webRequestBlocking | Permission | | This permission allows the extension to intercept, modify, or block any web request in real-time before it reaches its destination. Rated Critical because it can modify sensitive data (like passwords, credit cards) before encryption, redirect traffic to malicious sites, or block security updates. |
| webRequest | Permission | | This permission enables the extension to monitor and analyze all web requests made by the browser. Rated Critical because it can observe all network traffic including sensitive data, track browsing behavior, and gather authentication tokens. |
| scripting | Permission | | This permission allows injection and execution of JavaScript on any webpage. Rated Critical because it can modify page content, steal sensitive data, and inject malicious code into any site the extension has access to. |
| declarativeNetRequest | Permission | | This permission allows the extension to define rules to block, redirect, or modify network requests. Rated Critical because it can control all network traffic, potentially blocking security updates or redirecting to malicious sites. |
| <all_urls> | Host | | Broad host access — the extension can read/modify content on every website. |
| Dangerous Permission Combination: scripting,<all_urls>,webRequest | Risk Factor | | Enables sophisticated data theft through script injection and traffic monitoring |
| Dangerous Permission Combination | Risk Factor | | This extension can intercept, modify, and block web requests in real-time. |
| webNavigation | Permission | | This permission enables monitoring of all browser navigation events and transitions. Rated High because it can track every page visit, navigation method, and browsing pattern, potentially exposing sensitive browsing behavior and user activities. |
| browsingData | Permission | | This permission clears browsing data, history, and redis. Rated High because it can destroy evidence of malicious activity, clear security logs, and modify browser state. |
| Contextual Risk Factors | Risk Factor | | The following context increases the overall risk:• 20% increase: Access to sensitive domains increases potential impact• 10% increase: Early script execution enables pre-emptive content manipulation• 10% increase: About:blank access enables potential sandbox escape vectors |
| Broad Host Permissions | Risk Factor | | This extension has broad host permissions allowing it to access many or all websites. |
| Broad Content Script Access | Risk Factor | | This extension can inject scripts into any website. |
| tabs | Permission | | This permission enables tab management and monitoring. Rated Medium because it can track open tabs, access tab metadata, and monitor user browsing patterns. |
| management | Permission | | This permission manages other installed extensions. Rated Medium because it can enable/disable other extensions and modify their settings, with changes being visible to users. |
| storage | Permission | | This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads. |
| https://*.bugsnag.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://*.urban-vpn.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://www.google-analytics.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://ssl.google-analytics.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://google-analytics.com/ | Host | | Host permission — access limited to this URL pattern. |
| https://www.google.com/favicon.ico | Host | | Host permission — access limited to this URL pattern. |
| https://www.youtube.com/favicon.ico | Host | | Host permission — access limited to this URL pattern. |
| https://addons.mozilla.org/firefox/addon/urban-shield/* | Host | | Host permission — access limited to this URL pattern. |
| https://www.urban-vpn.com/thank-you-ext-shield/* | Host | | Host permission — access limited to this URL pattern. |
| https://www.urban-vpn.com/uninstall-ext-shield/* | Host | | Host permission — access limited to this URL pattern. |
| https://addons.mozilla.org/firefox/addon/urban-vpn//* | Host | | Host permission — access limited to this URL pattern. |
| https://authentication.urban-vpn.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://anti-mining-protection-toolbar.urban-vpn.com/api/rest/v2/* | Host | | Host permission — access limited to this URL pattern. |
| https://geo.geosurf.io/* | Host | | Host permission — access limited to this URL pattern. |
| https://config-toolbar.urban-vpn.com/rest/v1/configs/extensions/urban-shield/* | Host | | Host permission — access limited to this URL pattern. |
| https://api-pro.urban-vpn.com/rest/v1/* | Host | | Host permission — access limited to this URL pattern. |
| https://authentication.urban-vpn.com/rest/v1/* | Host | | Host permission — access limited to this URL pattern. |
| https://api-pro.urban-vpn.com/rest/v1/redirect/* | Host | | Host permission — access limited to this URL pattern. |
| Access to Sensitive Domains | Risk Factor | | This extension requests access to sensitive domains: https://www.google-analytics.com/*, https://ssl.google-analytics.com/*, https://google-analytics.com/, https://www.google.com/favicon.ico, https://anti-mining-protection-toolbar.urban-vpn.com/api/rest/v2/* |
| Early Content Script Execution | Risk Factor | | This extension runs content scripts at document_start. |
| About:blank Access | Risk Factor | | This extension can run content scripts in about:blank pages. |
| alarms | Permission | | This permission schedules periodic tasks. Rated Low because it can only trigger events at specified times without access to sensitive data. |