AnyDoc Translator - Translate Web and PDF
aopddeflghjljihihabdclejbojaomaf
Risk Score
3.88
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- nativeMessaging declared with unrecognized publisher — native app bridge not verifiable (+3.0 permissions).
- Privacy policy admits data collection AND third-party sharing but is NOT scoped to this extension → +10.0 privacy.
- cookies + *://*/* + scripting combo enables full cross-site session access and script injection.
- Privacy policy hosted on anydoctranslator.toolsmart.ai, not wps.com — domain mismatch undermines accountability.
- 7M-install reach amplifies any future supply-chain compromise or policy change.
Evidence
- nativeMessaging_unrecognized_publisher crx has_native_messaging=true, publisher_recognized=false; companion app identity unverifiable.
- privacy_policy_scope_fail api scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy pillar (v3.5-D rule).
- cookies_plus_all_urls manifest cookies + *://*/* host_permissions enables cross-site cookie access with 1.2x multiplier.
- dom_sink_innerhtml crx innerHTML user-controlled sink in assets/index.ts-DTDMPP1n.js; no CSP present.
- no_csp_mv3 manifest content_security_policy is null; MV3 default applies but dom_sink risk is elevated.
- verified_publisher_featured store verified_publisher=true, is_featured_by_google=true → reputation discounts applied, floor 2.0.
- 7M_installs_high_reach store 7,000,000 installs; blast radius is very large for any permission misuse.
- privacy_policy_domain_mismatch store Privacy policy on anydoctranslator.toolsmart.ai, dev email on wps.com — different domains.
Permissions Breakdown
- contextMenus low UI surface only, no data access.
- storage low Local settings persistence.
- unlimitedStorage low Large local data; no exfil vector alone.
- clipboardWrite medium Can write to clipboard; could inject content.
- tabs medium Can read tab URLs and metadata across sessions.
- scripting high Programmatic script injection into any page with host access.
- activeTab low Scoped to user-activated tab only.
- cookies high Can read/write cookies; paired with *://*/* is high-risk.
- nativeMessaging high Bridge to native app; publisher_recognized==false amplifies risk.
- *://*/* high Broad host access across all sites enables data interception.
Pillar Scores
Permissions5.50
Reputation2.00
Network3.50
Webstore2.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Scoring History
| <fsssiedxa xx psssiedx | 5.14 | Medium | review | 2026-08-11 |
| <fsssiedxa$'sssiedx | 5.14 | Medium | review | 2026-08-11 |
| <fsssiedxa | 5.04 | Medium | review | 2026-08-11 |
| <fsssiedxa$"sssiedx | 5.17 | Medium | review | 2026-08-11 |
| <fsssiedxa"sssiedx | 4.77 | Medium | review | 2026-08-09 |
| <fsssiedxa sssiedx | 4.54 | Medium | review | 2026-08-09 |
| fsssiedxa<sssiedx | 4.43 | Medium | review | 2026-08-09 |
| fsssiedxa"sssiedx | 4.31 | Medium | review | 2026-08-09 |
| sssieddrubricxsx | 5.28 | Medium | review | 2026-08-09 |
| v3.6 | 3.88 | Low | review | 2026-06-15 |
| v3.4-rev | 3.74 | Low | review | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-15 07:43
Listing SHA
fa5bee27f9bc…
Force block
— not fired
Score recovered
no
Elapsed
25.1s