VPNTestor Platform / Openscore VPN — 100/100
VPNTestor Platform completed an independent security audit of SingLinkVPN in July 2026.
The audit covered iOS, iPadOS, Android, macOS, Windows, Linux, Apple TV and the Web panel, including tunnelling, leaks, internal links, identity, local data, cross-platform consistency and remediation.
Because each platform has its own version and release process, the report records them separately instead of calling every client version 2.5.
No unresolved scored vulnerability was identified in scope. An early-2026 VPN-startup issue had been fixed; retesting did not reproduce it or identify a new vulnerability.
Report provenance, download, and integrity
This article republishes and summarises a third-party security audit issued by VPNTestor Platform. VPNTestor published the audit, testing, score, and signature; SingLinkVPN is reporting the findings and did not determine the audit conclusion. Refer to the VPNTestor original as the primary source.
Report file SHA-256: c925b9328a73365b2213157280ab828c8f7fed9bd25799af6d1dd6bf34c1dc2e
Named report signer: James Robert Smith
Signature status: signature provided. The VPNTestor original lists VPNTestor Platform / Openscore VPN as the signing party and James Robert Smith as lead auditor.
1. Audit summary
Critical risk: 0 found, 0 unresolved.
High risk: 0 found, 0 unresolved.
Medium risk: 0 found, 0 unresolved.
Low risk: 0 found, 0 unresolved.
The early-2026 VPN-startup attack surface was remediated before the formal audit and included in regression testing.
2. Audit statement
The auditor prepared this report from the tested products, environments, technical material and remediation evidence. SingLinkVPN supplied clients, test accounts and fixed builds; VPNTestor independently set the method, severity, results and score.
“Not found” means not identified or reproduced in this scope; it is not a permanent guarantee for every future version and environment.
3. About VPNTestor Platform
VPNTestor Platform, publicly known as Openscore VPN, evaluates VPN products and security. James Robert Smith led this audit using live clients, adverse networks, unauthorised-request simulation, traffic analysis, permissions and regression tests.
4. Platforms, versions and environments
iOS — SingLink 2.0.7 / App Store 1.0.7; iPhone 15 Pro and iPhone SE (3rd generation); iOS 18.x; evidence ID SLV-IOS-2026-01.
iPadOS — SingLink 2.0.7 / App Store 1.0.7; iPad Pro 11-inch and iPad (10th generation); iPadOS 18.x; evidence ID SLV-IPAD-2026-01.
Apple TV — SingLink 2.0.7 / App Store 1.0.7; Apple TV 4K (3rd generation); tvOS 17 or later; evidence ID SLV-TVOS-2026-01.
macOS Apple Silicon — SingLinkVPN 2.5.3 ARM64; MacBook Pro M3 Pro and MacBook Air M2; macOS 14/15; evidence ID SLV-MAC-ARM-2026-01.
macOS Intel — SingLinkVPN 2.5.3 x86_64; MacBook Pro 2019 Intel; macOS 13/14; evidence ID SLV-MAC-INTEL-2026-01.
Android — SingLinkVPN 2.1.3 APK; Google Pixel 9 Pro and Samsung Galaxy S24; Android 15/16; evidence ID SLV-ANDROID-2026-01.
Windows — SingLinkVPN 2.0.9 x64; Intel and AMD x64 test PCs; Windows 11 24H2 and Windows 10 22H2; evidence ID SLV-WIN-2026-01.
Linux Ubuntu/Debian — the legacy release remains listed; the new release is not yet published, and version/checksum details will be added after release.
Web user panel — July 2026 deployment; Web frontend and API; current Chrome, Edge, Firefox and Safari; evidence ID SLV-WEB-2026-01.
Version notes
App Store builds cover iOS/iPadOS/Apple TV; macOS 2.5.x has separate ARM64 and x86_64 packages; Android, Windows and Linux are independently versioned; Web is identified by deployment, Release or Commit.
5. Builds, installers and hashes
Build identifiers and hashes must come from the actual tested artefacts. The publisher must insert the real attachment SHA-256; estimates and random strings are prohibited.
iOS/iPadOS/Apple TV: refer to the official App Store release, Apple App Review, and platform code-signing status. Apple review is not a third-party security audit, and an audited IPA SHA-256 is not public.
macOS ARM64 2.5.3 (official-site DMG, 70,568,669 bytes) SHA-256: 5857cb3e6ded51362234bf2246958612cea10fab0d416f174faf7e9121708d24.
macOS Intel 2.5.3 (official-site DMG, 72,270,725 bytes) SHA-256: 5bba2c37a76ef8cb67bdfa15506c581d73faab73275bba73b83ec6ca5d110ad0.
Android 2.1.3 (official-site APK, 86,649,334 bytes) SHA-256: 81146be4136097eded546d9175fc9feba85174739d7a74a76563b4ebdb80d152.
Windows 2.0.9 (official-site EXE, 31,391,424 bytes) SHA-256: 2eb39c432aacdcb05aa93b89451e3022b2c6f55548ba56b52de25a4499007795.
Linux: the legacy release remains listed; the new release is not yet published, and its version and SHA-256 will be added after release.
These hashes identify current official distribution files retrieved from the SingLinkVPN website on 2026-07-27; they are not presented as the auditor-retained original test artefacts.
Web Release/Commit and container digest: not supplied in the source report as of 2026-07-27.
Published report SHA-256: c925b9328a73365b2213157280ab828c8f7fed9bd25799af6d1dd6bf34c1dc2e.
6. Audit scope
Scope covers tunnels, leaks, accounts/sessions, APIs/internal links, local data, the Web panel, updates and supply chain.
Normal VPN connection, active disconnection, abnormal server interruption, automatic reconnection, repeated requests, forced termination, sleep/wake, network switching, and route creation and cleanup.
DNS, IPv4, IPv6 and WebRTC leak protection; local-address exposure; traffic during interruption and reconnection; split and global modes.
Login, token validity and expiry, post-logout token reuse, unauthenticated access, account-ID tampering, cross-account access, subscription permissions and session revocation.
Unauthorised internal-configuration requests, invalid sessions, unofficial clients, parameter tampering, high-frequency requests, automated probing, internal-link isolation and rate limiting.
Local credentials, tokens, error logs, debug and diagnostic data, browsing and DNS records, source IP, cache and operating-system secure storage.
Web-panel authentication, account, order and subscription permissions, tokens, cookies, parameter tampering, cross-account access and logout invalidation.
Installer integrity, digital signatures, update source, downgrade resistance, third-party dependencies, hard-coded keys, release debug content and package permissions.
7. Network environments
Testing spans home broadband, dual stack, 4G/5G, public Wi-Fi, network migration, outage, abnormal DNS and loss/latency conditions.
IPv4 home broadband, IPv4/IPv6 dual stack, 4G, 5G and public Wi-Fi.
Wi-Fi to 5G and 5G to Wi-Fi migration, brief outage, abnormal DNS, high latency and packet loss.
8. Method
Every “passed” or “not found” statement maps to at least one case and evidence identifier.
Live-client operation, black-box functional testing and grey-box interface testing.
Packet analysis, DNS and routing tests, IPv4/IPv6 egress tests and WebRTC testing.
Unauthorised API access, session and token tests, rate-limit testing and local-data inspection.
Package and signature inspection, before/after remediation comparison, regression testing and cross-platform comparison.
9. Formal test cases
Network: VTP-SLV-NET-001…007; DNS: VTP-SLV-DNS-001; IPv4: VTP-SLV-IPV4-001; IPv6: VTP-SLV-IPV6-001; WebRTC: VTP-SLV-WRTC-001; routes: VTP-SLV-ROUTE-001.
Identity, API and Web: VTP-SLV-AUTH-001…004; VTP-SLV-API-001…004; VTP-SLV-WEB-001…003.
Privacy: VTP-SLV-PRIV-001…006.
10. Redacted packet and API evidence
DNS, IPv6, routing, WebRTC, API and internal-link evidence is retained in redacted form; secrets and production identifiers are removed before publication.
Packet captures: VTP-SLV-PCAP-DNS-001.pcapng, VTP-SLV-PCAP-IPV6-001.pcapng, VTP-SLV-PCAP-NETWORK-SWITCH-001.pcapng, VTP-SLV-PCAP-RECONNECT-001.pcapng and VTP-SLV-PCAP-WEBRTC-001.pcapng.
Redacted API records: VTP-SLV-API-001-unauthorized-request-redacted.json through VTP-SLV-API-004-internal-link-redacted.json.
Before publication, remove tokens, real server addresses, private domains, account and order identifiers, encryption keys and production credentials.
API evidence records the time, method, redacted endpoint ID, authentication state, HTTP status, response structure, internal-link exposure and final result.
11. Severity standard
Findings are classified critical, high, medium, low or informational by exploitability and impact.
Critical: mass sensitive-data exposure, remote-code execution, core-system control, complete authentication bypass or broad VPN-traffic exposure.
High: account takeover, unauthorised access, material privacy exposure, VPN bypass or access to protected configuration and internal links.
Medium: exploitable under specific conditions with a limited platform, feature or data impact.
Low: limited direct impact but weakens defence or increases risk when combined with other conditions.
Informational: no directly exploitable vulnerability; a security-engineering improvement.
12. Results
All four scored severity levels contain zero unresolved findings. The repaired startup issue was a priority regression case.
Critical risk: 0 found, 0 unresolved.
High risk: 0 found, 0 unresolved.
Medium risk: 0 found, 0 unresolved.
Low risk: 0 found, 0 unresolved.
The early-2026 VPN-startup attack surface was remediated before the formal audit and included in regression testing.
13. VPN-startup issue and remediation
The startup flow obtains connection configuration from the backend; weak identity, session, request or isolation controls could create a probing or internal-data exposure surface.
The fix strengthened identity and session validation, unofficial-client restrictions, anomaly/rate controls, internal-link isolation, response minimisation, anti-automation and client–server authorisation.
The VPN-startup flow obtains connection configuration from the backend; insufficient identity, session, request or data-isolation controls could create unauthorised probing, high-frequency request or internal-data exposure surfaces.
The remediation strengthened authentication for VPN-start requests and session-validity checks.
Restrictions on unofficial clients, abnormal-request detection, rate limiting and anti-automation controls were added.
Internal links were isolated from public interfaces, response data was reduced, and client-to-backend authorisation was strengthened.
Retesting could not reproduce the original issue; protected configuration and internal links remained unavailable, and no new vulnerability was identified.
Remediated, retested and closed.
14. DNS, IPv4, IPv6 and WebRTC
No reproducible DNS, IPv4, IPv6, WebRTC or route bypass, prolonged unprotected flow, or false connected state was found in the tested scenarios.
15. Account and Web-panel security
Unauthenticated or expired sessions could not access protected data; parameter changes did not expose another account; logout invalidated the session as expected.
16. Privacy and data handling
No client-generated record of browsing content, DNS queries, complete activity, site lists or raw traffic was observed. Registration email/order records are not VPN activity logs.
Within the observable scope, the clients were not seen creating records of browsing content, browsing history, DNS queries, complete activity, site lists or raw traffic.
Local credentials, tokens, cache, errors and diagnostic data were included in secure-storage and data-minimisation checks.
Registration virtual-email, order and subscription records serve account, subscription and support processing; they are not VPN network-activity logs.
Public evidence must first remove data that can identify users, accounts, nodes, credentials or production systems.
17. Cross-platform conclusions
Every listed platform passed its applicable connection, leak, routing, recovery, identity, local-data or permission checks, limited to the stated versions and environments.
iOS, iPadOS and Apple TV: connection, recovery, leak, account and local-data checks passed.
macOS Apple Silicon and Intel: TUN, DNS, routing, sleep recovery, compatibility and internal-link checks passed.
Android: VPN Service, background connection, network switching, IPv6 and local-data checks passed.
Windows: tunnel, DNS, system-route, interruption and reconnection checks passed.
Ubuntu and Debian: installation, service startup, tunnel, DNS, routing and permission checks passed.
Web user panel: login, session, account-permission and cross-account access checks passed.
18. Open source and technical transparency
SingLinkVPN publishes architecture, security/privacy models, benchmark methods, data formats, research tools and evidence rules, but open source alone does not prove security.
19. 100-point formula
The seven categories total 100 points. No scored deduction applied; remediation retesting passed and found no new vulnerability.
VPN tunnel, DNS and network-leak protection: 25 points.
Account, API and internal-link security: 20 points.
Local client data and privacy controls: 15 points.
Cross-platform security consistency: 10 points.
Web panel and session security: 10 points.
Updates, packages and supply-chain checks: 10 points.
Known-issue remediation and retesting: 10 points.
Deduction per finding: critical 30, high 15, medium 7 and low 2 points; informational recommendations do not directly deduct points.
100/100
20. Why the score is 100
The score reflects zero unresolved scored findings, broad platform coverage, passed leak/permission tests, protected internal data and successful remediation. It is not a lifetime guarantee.
21. User action
Users on old builds should update through their platform’s official channel. Current users need no additional action under this audit result.
Download only from official SingLinkVPN channels or authorised app stores.
Do not use modified builds from unknown sources; keep the operating system supported and the client current.
Do not share account credentials; re-authenticate or refresh server configuration if a connection behaves abnormally.
22. Limitations
The result applies only to the July 2026 versions, devices, systems, networks, cases and product state; later changes require appropriate retesting.
The audit applies only to the July 2026 versions, devices, operating systems, networks, cases and observed product state listed in the report.
It does not cover features, protocols, dependencies or backend changes introduced after completion.
Material changes to protocols, clients, TV or Web panels, identity systems, server configuration, dependencies or release processes require renewed testing.
23. Final conclusion
All listed platforms and scored controls passed. No unresolved critical, high, medium or low-risk vulnerability was identified in scope; final rating: 100/100.
24. Signature
Signed for VPNTestor Platform by audit lead James Robert Smith.
Organisation: VPNTestor Platform; public name: Openscore VPN.
Audit lead and signer: James Robert Smith.
Report version: 1.0.
Audit date and signing date: 2026-07-27.
Institutional email: office@vpntestor.com.
Signature status: signature provided. The VPNTestor original lists VPNTestor Platform / Openscore VPN as the signing party and James Robert Smith as lead auditor.
Report SHA-256: c925b9328a73365b2213157280ab828c8f7fed9bd25799af6d1dd6bf34c1dc2e.
