DeepL: translate and write with AI
cofdbpoegempjloogbagkncekinflcnj
Risk Score
4.16
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy covers deepl.com broadly but is not scoped to this extension; admits data collection and third-party sharing.
- content_scripts on <all_urls> with webRequest and cookies permissions creates broad page-access surface across all sites.
- new Function() constructor found in bundled tesseract/worker.min.js; limited risk as it appears in a globalThis detection pattern.
- No developer_name field populated in manifest; deepl.com domain resolves and email matches but store identity gap exists.
- AI translation extension processes page content on 4M installs; data routed to deepl.com API endpoints.
Evidence
- content_scripts_broad manifest content_scripts matches <all_urls> — injects into every page visited.
- webRequest+cookies manifest webRequest and cookies declared; host_permissions scoped to *.deepl.com only.
- privacy_policy_not_extension_scoped api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
- function_constructor crx new Function() in tesseract/worker.min.js — globalThis detection pattern, low exploitation risk.
- featured_by_google store is_featured_by_google=true; provides partial trust signal.
- no_bad_hosts_or_monetization api threat_intel shows empty bad_host_hits, affiliate_hits, monetization_hits.
- no_cves crx cve_findings_raw is empty; no known vulnerable libraries detected.
- recently_updated store months_since_update=0; actively maintained extension.
Permissions Breakdown
- activeTab low Accesses current tab on user action only.
- storage low Local settings/preferences storage.
- contextMenus low Adds right-click translate option.
- tabs medium Can read tab URLs and titles across all tabs.
- scripting medium Can inject scripts into pages; paired with <all_urls> content scripts.
- declarativeNetRequest medium Can modify/block network requests declaratively.
- identity low OAuth identity for user account login.
- tts low Text-to-speech for translation playback.
- alarms low Periodic background tasks.
- webRequest high Can observe all network requests matching host_permissions.
- cookies high Can read/write cookies; scoped to *.deepl.com only.
- sidePanel low Side panel UI for translation interface.
- content_scripts:<all_urls> high Injects into every page; core translation function but broad surface.
Pillar Scores
Permissions5.00
Reputation3.50
Network2.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00
Scoring History
| <fsssiedxa'sssiedx | 3.58 | Low | review | 2026-08-09 |
| fsssiedx<sssiedx | 3.47 | Low | review | 2026-08-09 |
| <fsssiedxa"sssiedx | 3.41 | Low | review | 2026-08-04 |
| <fsssiedxa xx psssiedx | 3.55 | Low | allow | 2026-08-04 |
| <fsssiedxa$'sssiedx | 2.45 | Low | review | 2026-08-04 |
| <fsssiedxa"sssiedx | 3.76 | Low | review | 2026-08-04 |
| <fsssiedxa$"sssiedx | 3.62 | Low | review | 2026-08-04 |
| <fsssiedxa'sssiedx | 3.58 | Low | review | 2026-08-04 |
| fsssiedxa<sssiedx | 3.73 | Low | review | 2026-08-04 |
| %0dfsssiedxa<sssiedx | 3.54 | Low | review | 2026-07-30 |
| 4.12 | Medium | review | 2026-07-30 | |
| sssieddrubricxsx | 4.04 | Medium | review | 2026-07-30 |
| fsssiedxa"sssiedx | 3.62 | Low | review | 2026-07-28 |
| v3.6 | 4.16 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:25
Listing SHA
30d9f7f573e2…
Force block
— not fired
Score recovered
no
Elapsed
23.9s