Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Immersive Translate: AI Web, PDF & Video Translator

bpoadfkcbjbfhfodiogcnhhhpibjhbnh
Risk Score
4.08
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category TranslationTool
Installs 3,000,000
Rating 3.9
Last updated 2026-08-07
Manifest version MV3
CSP present ✅ yes
Developer support@immersivetranslate.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension, but data_collection and third_party_sharing are true → scores maximum privacy penalty.
  • webRequest + declarativeNetRequestWithHostAccess + <all_urls> content scripts give broad per-request visibility across every site visited.
  • 6 external JS hosts (github.com, huggingface.co, raw.githubusercontent.com, modelscope.cn, picocss.com) expand supply-chain risk surface.
  • uninstall_url_hijack flag is true — extension sets an uninstall URL to a third party.
  • AI translation extension processes full page content on 3M+ installs; exfil risk if compromised.

Evidence

  • privacy_policy_generic store Policy URL is Google account-level policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 rule D).
  • webRequest+all_urls manifest webRequest paired with <all_urls> host permission: can observe all requests. ×1.2 multiplier applied.
  • uninstall_url_hijack crx uninstall_url_hijack=true; target not extractable but flag is set → +3.0 Webstore.
  • external_js_hosts crx 6 external hosts: github.com, huggingface.co, raw.githubusercontent.com, modelscope.cn, picocss.com, immersivetranslate.com.
  • verified_publisher+featured store verified_publisher=true and is_featured_by_google=true; discounts applied to Reputation (floor 2.0).
  • function_constructor_in_tesseract crx new Function() in tesseract/worker.min.js; common in bundled OCR workers but raises code quality score.
  • ai_page_content store AI translation processes full page content on 3M installs; high exfil impact if supply chain compromised.
  • developer_name_missing store developer_name field is empty string; identity relies solely on email domain immersivetranslate.com.

Permissions Breakdown

  • storage low Stores user settings locally.
  • activeTab low Access current tab on user gesture only.
  • contextMenus low Adds right-click menu items; low risk.
  • webRequest high Can observe all HTTP requests across all URLs.
  • declarativeNetRequestWithHostAccess high Can modify/block network requests with broad host access.
  • declarativeNetRequestFeedback low Receives feedback on matched declarative rules; low standalone risk.
  • declarativeNetRequest medium Can block/redirect requests declaratively.
  • offscreen low Offscreen document for background DOM ops; limited surface.
  • sidePanel low Opens side panel UI; no data risk alone.
  • <all_urls> (host) high Content scripts run on every site; paired with webRequest greatly expands surface.

Pillar Scores

Permissions5.50
Reputation2.00
Network3.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Scoring History

sssieddrubricxsx 4.52 Medium review 2026-08-13
v3.6 4.08 Medium review 2026-06-16
v3.4-rev 4.12 Medium review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:22
Listing SHA ddd4792085c0…
Force block — not fired
Score recovered no
Elapsed 26.1s