Immersive Translate: AI Web, PDF & Video Translator
bpoadfkcbjbfhfodiogcnhhhpibjhbnh
Risk Score
4.08
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension, but data_collection and third_party_sharing are true → scores maximum privacy penalty.
- webRequest + declarativeNetRequestWithHostAccess + <all_urls> content scripts give broad per-request visibility across every site visited.
- 6 external JS hosts (github.com, huggingface.co, raw.githubusercontent.com, modelscope.cn, picocss.com) expand supply-chain risk surface.
- uninstall_url_hijack flag is true — extension sets an uninstall URL to a third party.
- AI translation extension processes full page content on 3M+ installs; exfil risk if compromised.
Evidence
- privacy_policy_generic store Policy URL is Google account-level policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 rule D).
- webRequest+all_urls manifest webRequest paired with <all_urls> host permission: can observe all requests. ×1.2 multiplier applied.
- uninstall_url_hijack crx uninstall_url_hijack=true; target not extractable but flag is set → +3.0 Webstore.
- external_js_hosts crx 6 external hosts: github.com, huggingface.co, raw.githubusercontent.com, modelscope.cn, picocss.com, immersivetranslate.com.
- verified_publisher+featured store verified_publisher=true and is_featured_by_google=true; discounts applied to Reputation (floor 2.0).
- function_constructor_in_tesseract crx new Function() in tesseract/worker.min.js; common in bundled OCR workers but raises code quality score.
- ai_page_content store AI translation processes full page content on 3M installs; high exfil impact if supply chain compromised.
- developer_name_missing store developer_name field is empty string; identity relies solely on email domain immersivetranslate.com.
Permissions Breakdown
- storage low Stores user settings locally.
- activeTab low Access current tab on user gesture only.
- contextMenus low Adds right-click menu items; low risk.
- webRequest high Can observe all HTTP requests across all URLs.
- declarativeNetRequestWithHostAccess high Can modify/block network requests with broad host access.
- declarativeNetRequestFeedback low Receives feedback on matched declarative rules; low standalone risk.
- declarativeNetRequest medium Can block/redirect requests declaratively.
- offscreen low Offscreen document for background DOM ops; limited surface.
- sidePanel low Opens side panel UI; no data risk alone.
- <all_urls> (host) high Content scripts run on every site; paired with webRequest greatly expands surface.
Pillar Scores
Permissions5.50
Reputation2.00
Network3.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00
Scoring History
| sssieddrubricxsx | 4.52 | Medium | review | 2026-08-13 |
| v3.6 | 4.08 | Medium | review | 2026-06-16 |
| v3.4-rev | 4.12 | Medium | review | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:22
Listing SHA
ddd4792085c0…
Force block
— not fired
Score recovered
no
Elapsed
26.1s