Zent Translate
bincmiainjofjnhchmcalkanjebghoen
Risk Score
4.01
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Free-webmail dev email (sh01.bid@gmail.com), no dev name, no verified publisher — identity unverifiable.
- Content scripts inject on ALL http/https pages (http://*/* https://*/*) giving broad page-read/write capability.
- Privacy policy admits data collection and third-party sharing; scoped to extension but retention and sharing scope raise concern.
- No CSP on MV3 extension with scripting + broad content scripts; no runtime code findings but surface remains.
- Unknown host agtranslate.com in host_permissions; unrecognized third-party contact beyond stated translation providers.
Evidence
- free_webmail_dev_no_name store Developer email sh01.bid@gmail.com is free webmail; developer_name is empty; no verified publisher badge.
- broad_content_scripts manifest content_scripts_matches includes http://*/* and https://*/* — scripts run on every page.
- privacy_third_party_sharing api privacy_policy_classification: fetched=true, scope_extension=true, data_collection=true, third_party_sharing=true, retention=true.
- no_csp manifest content_security_policy is null; MV3 default applies but no explicit hardening.
- unknown_host_agtranslate manifest host_permissions includes https://agtranslate.com/* — not a recognized translation provider.
- js_external_hosts_diversity crx 8 external JS hosts across 3 countries (AR, IN, US); includes react.dev, i18next.com, baidu, bing, deepl, google.
- is_featured_by_google store Extension carries Google Featured badge — partial trust signal.
- search_engines_3_non_newtab api threat_intel.search_engine_count=3 (baidu, bing, google) but category is TranslationTool, not NewTab — expected for multi-engine translation.
Permissions Breakdown
- storage low Stores extension settings locally; standard for translation tools.
- sidePanel low Opens side panel UI; no cross-site data access.
- contextMenus low Adds right-click translate option; low risk.
- declarativeNetRequest medium Can modify network requests declaratively; moderate risk without host filter.
- scripting high Injects scripts into pages; paired with http://*/* and https://*/* content scripts = broad reach.
- host:https://translate.googleapis.com/* low Google Translate API; expected for translation category.
- host:https://fanyi.baidu.com/* low Baidu translation API; expected.
- host:https://www.deepl.com/* low DeepL API; expected.
- host:https://agtranslate.com/* medium Unknown third-party domain; not a recognized translation provider.
- content_scripts: http://*/* https://*/* high Injects scripts on every HTTP/HTTPS page; broad execution surface.
Pillar Scores
Permissions4.80
Reputation7.00
Network4.50
Webstore4.50
Maintenance0.00
Privacy2.00
Code Quality0.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:20
Listing SHA
3d809a21577d…
Force block
— not fired
Score recovered
no
Elapsed
24.6s