Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Manga Translator

binegohghebdmajnfnfgjijikalfhhec
Risk Score
6.32
Risk Level: High
Recommendation: 🚫 BLOCK
Category TranslationTool
Installs 623
Rating 2.4
Last updated 2025-02-18 (18 months ago)
Manifest version MV3
CSP present ❌ no
Developer cebibacy@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Free-webmail dev (gmail), no developer name, no verified publisher — anonymous operator with broad host access.
  • Uninstall URL hijack + install URL hijack flagged; classic traffic-monetization fingerprint.
  • 12 external JS hosts including Alibaba/Aliyun telemetry infra and unrelated domains (livepolls.app, video.deletetweets.ai).
  • scripting + <all_urls> + content_scripts on every page; can read/modify all web content persistently.
  • Geo-diverse JS hosting across CN/SG/US/CA with Aliyun telemetry endpoints raises data-exfiltration concern.

Evidence

  • free_webmail_no_devname store Developer email cebibacy@gmail.com, developer_name empty — anonymous operator.
  • uninstall_url_hijack crx uninstall_url_hijack=true; extension registers custom uninstall redirect.
  • install_url_hijack crx install_url_hijack=true; onInstalled opens /src/pages/welcome/index.html.
  • broad_host_access manifest host_permissions http://*/* + https://*/* and content_scripts on <all_urls>.
  • aliyun_telemetry_hosts crx JS contacts arms-retcode.aliyuncs.com, arms-retcode-sg.aliyuncs.com — Alibaba telemetry infra.
  • unrelated_external_hosts crx livepolls.app and video.deletetweets.ai present; unrelated to manga translation.
  • geo_diversity crx JS hosts span 4 countries (CA, CN, SG, US); CN-based telemetry endpoints.
  • small_install_high_perm store 623 installs with HIGH-tier permissions (scripting + broad host) — tail attack surface.

Permissions Breakdown

  • sidePanel low UI panel; low risk on its own.
  • identity medium Can access OAuth tokens; potential account linkage.
  • identity.email medium Exposes user email address to extension.
  • storage low Local data persistence; low risk.
  • contextMenus low Adds right-click menu items; low risk.
  • scripting high Executes arbitrary scripts in page context on all URLs.
  • activeTab low Limited to current tab on user action; low risk.
  • http://*/* high Broad host access — all HTTP sites.
  • https://*/* high Broad host access — all HTTPS sites.
  • <all_urls> (content_scripts) high Content scripts injected on every page; persistent DOM access.

Pillar Scores

Permissions7.50
Reputation8.00
Network6.50
Webstore7.50
Maintenance6.00
Privacy1.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 09:56
Listing SHA c4cb436a2635…
Force block — not fired
Score recovered no
Elapsed