Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Google Translate

aapbdbdomjkkjkaonfhkkikfgjllcleb
Risk Score
3.61
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category TranslationTool
Installs 34,000,000
Rating 4.2
Last updated 2026-07-01 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer google-translate-chrome-extension-owners@google.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic corporate policy; does not scope data collection to this extension specifically.
  • Content scripts declared on <all_urls> giving broad page-read reach across all sites.
  • 21 months since last update; moderately stale for a 34M-install extension.
  • No CSP defined (MV3 default applies, but explicit policy absent).
  • Generic Google policy admits data collection and third-party sharing without extension-specific disclosure.

Evidence

  • recognized_org store Developer email @google.com, confirmed owner of Google brand; not impersonation.
  • privacy_policy_scope api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy per v3.5 rule D.
  • content_scripts_all_urls manifest content_scripts_matches includes <all_urls>; broad host reach on every visited page.
  • maintenance_stale store Last updated Sep 2024; 21 months since update → +6.0 maintenance pillar.
  • no_cve_findings crx cve_findings_raw empty; no known vulnerable libraries detected.
  • no_code_findings crx code_findings_raw empty; obfuscation_score=0.0; no malicious patterns found.
  • threat_intel_clean api No bad_host_hits, affiliate_hits, or monetization_hits; developer domain google.com resolves.
  • featured_by_google store is_featured_by_google=true; recognized org discount applied; reputation floored at 2.0.

Permissions Breakdown

  • activeTab low Access only to current tab on user action; scoped and low-risk.
  • contextMenus low Adds right-click menu items; no data access by itself.
  • storage low Local preferences storage; no cross-site risk.
  • offscreen low MV3 offscreen document for background tasks; limited surface.
  • scripting medium Can inject scripts into pages; paired with <all_urls> content_scripts raises capability.
  • content_scripts:<all_urls> high Content scripts run on every page, broad host reach for a translation tool.

Pillar Scores

Permissions3.00
Reputation2.00
Network2.00
Webstore2.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Scoring History

fsssiedxn3f645fa4zafdsaxax><!--></ScRiPt>asddn3f645fa4zsssiedx 2.74 Low review 2026-08-30
sssiedn4613b38bdp727562726963xsx 2.83 Low review 2026-08-30
%22fsssiedxe sssiedx 2.81 Low review 2026-08-24
%27fsssiedxe$"sssiedx 2.77 Low allow 2026-08-24
&#x27;fsssiedxe$'sssiedx 3.07 Low review 2026-08-24
&#x22;fsssiedxe$'sssiedx 3.04 Low review 2026-08-24
fsssiedxe<sssiedx 3.19 Low review 2026-08-24
<fsssiedx{$'sssiedx 2.55 Low review 2026-08-24
<fsssiedx{$"sssiedx 2.37 Low review 2026-08-24
<fsssiedx{"sssiedx 2.92 Low allow 2026-08-17
xx pfsssiedxb$'sssiedx 2.73 Low review 2026-08-17
%27fsssiedxb$'sssiedx 2.81 Low review 2026-08-17
2.57 Low review 2026-08-17
fsssiedxb<sssiedx 2.69 Low allow 2026-08-17
fsssiedx<sssiedx 2.92 Low review 2026-08-17
fsssiedxa"sssiedx 2.88 Low review 2026-08-14
sssieddrubricxsx 2.92 Low review 2026-08-14
v1 3.08 Low allow 2026-07-02
v3.6 3.61 Low review 2026-06-16
v3.4-rev 3.31 Low review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:14
Listing SHA a10b2eef7bff…
Force block — not fired
Score recovered no
Elapsed 24.3s