会译:一站式 AI 翻译 Agent|对照式DeepL翻译|DeepSeek划词翻译|免费
dgeiaiglmhdhajbpfbmajaajdlfdinpi
Risk Score
5.28
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and 3rd-party sharing (score: 10.0).
- webRequest + scripting + <all_urls>: can read/modify all network traffic and inject code on every site visited.
- Developer domain nightingales.cn does not resolve; no verified business identity behind the extension.
- Uninstall URL hijack detected; extension registers a redirect on removal to an unknown target.
- YouTube brand impersonation flagged (not a verified YouTube partner); AI translation extension processing full page content on all sites.
Evidence
- privacy_policy_generic store Privacy URL points to Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true — scores +10.0.
- developer_domain_no_resolve api nightingales.cn does not resolve; developer identity unverifiable despite verified_publisher=true.
- uninstall_url_hijack manifest uninstall_url_hijack=true with null target recorded; +3.0 Webstore per rubric.
- webRequest_all_urls manifest webRequest + <all_urls> + scripting: can observe and inject into all HTTP traffic.
- brand_impersonation_youtube store brand_mention.is_impersonation=true for YouTube; developer not confirmed owner; +2.0 Reputation.
- no_developer_name store developer_name is empty string; no 'Offered by' identity disclosed.
- js_external_hosts crx Extension contacts huiyiai.net and tinyurl.com; tinyurl is a link-shortener with opaque redirect destination.
- csp_absent_mv3 manifest csp_present=false on MV3; MV3 provides strict default but no CSP amplifier applies per v2 rules.
Permissions Breakdown
- storage low Standard local data persistence.
- unlimitedStorage low Extended storage; low risk alone.
- scripting high Executes arbitrary scripts in page context; paired with <all_urls> is high risk.
- tts low Text-to-speech output; no data exfil risk.
- contextMenus low Adds right-click menu items; minor surface.
- webRequest high Can observe all network requests across all URLs.
- sidePanel low Opens extension UI in side panel; low risk.
- <all_urls> (host_permission) high Broad host access paired with scripting and webRequest multiplies risk significantly.
Pillar Scores
Permissions7.00
Reputation5.50
Network4.50
Webstore5.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 09:47
Listing SHA
d1d6066d252a…
Force block
— not fired
Score recovered
no
Elapsed
—