Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

AnyDoc Translator - Translate Web and PDF

aopddeflghjljihihabdclejbojaomaf
Risk Score
3.88
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category TranslationTool
Installs 6,000,000
Rating 4.6
Last updated 2026-08-06
Manifest version MV3
CSP present ❌ no
Developer feedback@wps.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • nativeMessaging declared with unrecognized publisher — native app bridge not verifiable (+3.0 permissions).
  • Privacy policy admits data collection AND third-party sharing but is NOT scoped to this extension → +10.0 privacy.
  • cookies + *://*/* + scripting combo enables full cross-site session access and script injection.
  • Privacy policy hosted on anydoctranslator.toolsmart.ai, not wps.com — domain mismatch undermines accountability.
  • 7M-install reach amplifies any future supply-chain compromise or policy change.

Evidence

  • nativeMessaging_unrecognized_publisher crx has_native_messaging=true, publisher_recognized=false; companion app identity unverifiable.
  • privacy_policy_scope_fail api scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy pillar (v3.5-D rule).
  • cookies_plus_all_urls manifest cookies + *://*/* host_permissions enables cross-site cookie access with 1.2x multiplier.
  • dom_sink_innerhtml crx innerHTML user-controlled sink in assets/index.ts-DTDMPP1n.js; no CSP present.
  • no_csp_mv3 manifest content_security_policy is null; MV3 default applies but dom_sink risk is elevated.
  • verified_publisher_featured store verified_publisher=true, is_featured_by_google=true → reputation discounts applied, floor 2.0.
  • 7M_installs_high_reach store 7,000,000 installs; blast radius is very large for any permission misuse.
  • privacy_policy_domain_mismatch store Privacy policy on anydoctranslator.toolsmart.ai, dev email on wps.com — different domains.

Permissions Breakdown

  • contextMenus low UI surface only, no data access.
  • storage low Local settings persistence.
  • unlimitedStorage low Large local data; no exfil vector alone.
  • clipboardWrite medium Can write to clipboard; could inject content.
  • tabs medium Can read tab URLs and metadata across sessions.
  • scripting high Programmatic script injection into any page with host access.
  • activeTab low Scoped to user-activated tab only.
  • cookies high Can read/write cookies; paired with *://*/* is high-risk.
  • nativeMessaging high Bridge to native app; publisher_recognized==false amplifies risk.
  • *://*/* high Broad host access across all sites enables data interception.

Pillar Scores

Permissions5.50
Reputation2.00
Network3.50
Webstore2.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Scoring History

<fsssiedxa xx psssiedx 5.14 Medium review 2026-08-11
<fsssiedxa$'sssiedx 5.14 Medium review 2026-08-11
<fsssiedxa 5.04 Medium review 2026-08-11
<fsssiedxa$"sssiedx 5.17 Medium review 2026-08-11
<fsssiedxa"sssiedx 4.77 Medium review 2026-08-09
<fsssiedxa sssiedx 4.54 Medium review 2026-08-09
fsssiedxa<sssiedx 4.43 Medium review 2026-08-09
fsssiedxa"sssiedx 4.31 Medium review 2026-08-09
sssieddrubricxsx 5.28 Medium review 2026-08-09
v3.6 3.88 Low review 2026-06-15
v3.4-rev 3.74 Low review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-15 07:43
Listing SHA fa5bee27f9bc…
Force block — not fired
Score recovered no
Elapsed 25.1s