Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

DeepL: translate and write with AI

cofdbpoegempjloogbagkncekinflcnj
Risk Score
4.16
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category TranslationTool
Installs 4,000,000
Rating 4.7
Last updated 2026-07-28 (1 months ago)
Manifest version MV3
CSP present ✅ yes
Developer team-integrations@deepl.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy covers deepl.com broadly but is not scoped to this extension; admits data collection and third-party sharing.
  • content_scripts on <all_urls> with webRequest and cookies permissions creates broad page-access surface across all sites.
  • new Function() constructor found in bundled tesseract/worker.min.js; limited risk as it appears in a globalThis detection pattern.
  • No developer_name field populated in manifest; deepl.com domain resolves and email matches but store identity gap exists.
  • AI translation extension processes page content on 4M installs; data routed to deepl.com API endpoints.

Evidence

  • content_scripts_broad manifest content_scripts matches <all_urls> — injects into every page visited.
  • webRequest+cookies manifest webRequest and cookies declared; host_permissions scoped to *.deepl.com only.
  • privacy_policy_not_extension_scoped api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • function_constructor crx new Function() in tesseract/worker.min.js — globalThis detection pattern, low exploitation risk.
  • featured_by_google store is_featured_by_google=true; provides partial trust signal.
  • no_bad_hosts_or_monetization api threat_intel shows empty bad_host_hits, affiliate_hits, monetization_hits.
  • no_cves crx cve_findings_raw is empty; no known vulnerable libraries detected.
  • recently_updated store months_since_update=0; actively maintained extension.

Permissions Breakdown

  • activeTab low Accesses current tab on user action only.
  • storage low Local settings/preferences storage.
  • contextMenus low Adds right-click translate option.
  • tabs medium Can read tab URLs and titles across all tabs.
  • scripting medium Can inject scripts into pages; paired with <all_urls> content scripts.
  • declarativeNetRequest medium Can modify/block network requests declaratively.
  • identity low OAuth identity for user account login.
  • tts low Text-to-speech for translation playback.
  • alarms low Periodic background tasks.
  • webRequest high Can observe all network requests matching host_permissions.
  • cookies high Can read/write cookies; scoped to *.deepl.com only.
  • sidePanel low Side panel UI for translation interface.
  • content_scripts:<all_urls> high Injects into every page; core translation function but broad surface.

Pillar Scores

Permissions5.00
Reputation3.50
Network2.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Scoring History

<fsssiedxa&#x27;sssiedx 3.58 Low review 2026-08-09
fsssiedx<sssiedx 3.47 Low review 2026-08-09
<fsssiedxa&#x22;sssiedx 3.41 Low review 2026-08-04
<fsssiedxa xx psssiedx 3.55 Low allow 2026-08-04
<fsssiedxa$'sssiedx 2.45 Low review 2026-08-04
<fsssiedxa"sssiedx 3.76 Low review 2026-08-04
<fsssiedxa$"sssiedx 3.62 Low review 2026-08-04
<fsssiedxa'sssiedx 3.58 Low review 2026-08-04
fsssiedxa<sssiedx 3.73 Low review 2026-08-04
%0dfsssiedxa<sssiedx 3.54 Low review 2026-07-30
4.12 Medium review 2026-07-30
sssieddrubricxsx 4.04 Medium review 2026-07-30
fsssiedxa&#x22;sssiedx 3.62 Low review 2026-07-28
v3.6 4.16 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:25
Listing SHA 30d9f7f573e2…
Force block — not fired
Score recovered no
Elapsed 23.9s