Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Zent Translate

bincmiainjofjnhchmcalkanjebghoen
Risk Score
4.01
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category TranslationTool
Installs 100,000
Rating 4.6
Last updated 2026-05-30 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer sh01.bid@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Free-webmail dev email (sh01.bid@gmail.com), no dev name, no verified publisher — identity unverifiable.
  • Content scripts inject on ALL http/https pages (http://*/* https://*/*) giving broad page-read/write capability.
  • Privacy policy admits data collection and third-party sharing; scoped to extension but retention and sharing scope raise concern.
  • No CSP on MV3 extension with scripting + broad content scripts; no runtime code findings but surface remains.
  • Unknown host agtranslate.com in host_permissions; unrecognized third-party contact beyond stated translation providers.

Evidence

  • free_webmail_dev_no_name store Developer email sh01.bid@gmail.com is free webmail; developer_name is empty; no verified publisher badge.
  • broad_content_scripts manifest content_scripts_matches includes http://*/* and https://*/* — scripts run on every page.
  • privacy_third_party_sharing api privacy_policy_classification: fetched=true, scope_extension=true, data_collection=true, third_party_sharing=true, retention=true.
  • no_csp manifest content_security_policy is null; MV3 default applies but no explicit hardening.
  • unknown_host_agtranslate manifest host_permissions includes https://agtranslate.com/* — not a recognized translation provider.
  • js_external_hosts_diversity crx 8 external JS hosts across 3 countries (AR, IN, US); includes react.dev, i18next.com, baidu, bing, deepl, google.
  • is_featured_by_google store Extension carries Google Featured badge — partial trust signal.
  • search_engines_3_non_newtab api threat_intel.search_engine_count=3 (baidu, bing, google) but category is TranslationTool, not NewTab — expected for multi-engine translation.

Permissions Breakdown

  • storage low Stores extension settings locally; standard for translation tools.
  • sidePanel low Opens side panel UI; no cross-site data access.
  • contextMenus low Adds right-click translate option; low risk.
  • declarativeNetRequest medium Can modify network requests declaratively; moderate risk without host filter.
  • scripting high Injects scripts into pages; paired with http://*/* and https://*/* content scripts = broad reach.
  • host:https://translate.googleapis.com/* low Google Translate API; expected for translation category.
  • host:https://fanyi.baidu.com/* low Baidu translation API; expected.
  • host:https://www.deepl.com/* low DeepL API; expected.
  • host:https://agtranslate.com/* medium Unknown third-party domain; not a recognized translation provider.
  • content_scripts: http://*/* https://*/* high Injects scripts on every HTTP/HTTPS page; broad execution surface.

Pillar Scores

Permissions4.80
Reputation7.00
Network4.50
Webstore4.50
Maintenance0.00
Privacy2.00
Code Quality0.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:20
Listing SHA 3d809a21577d…
Force block — not fired
Score recovered no
Elapsed 24.6s