Torii Image Translator — AI Manga Translator, Manhwa Translator ...
gkdekajjngdkocgiealohleibhdjhoed
Risk Score
3.07
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- declarativeNetRequestWithHostAccess + <all_urls> allows network-level interception on every site visited.
- External JS hosts include raw.github.com and stuartk.com — non-dev-controlled domains could serve updated code.
- function_constructor (new Function()) in zip.js enables dynamic code execution.
- No CSP declared (MV3 default helps but no explicit restriction); dom_sink_innerhtml_userctrl present.
- No developer name listed in store; AI translation of page content processed via dev API.
Evidence
- declarativeNetRequestWithHostAccess + <all_urls> manifest HIGH permission paired with broad host access; can intercept requests sitewide.
- external_hosts_non_dev crx raw.github.com, stuartk.com, stuk.github.io contacted — third-party non-dev-controlled JS endpoints.
- verified_publisher + featured store Extension carries both verified publisher and Google featured badges; reputation discounts applied.
- privacy_policy_adequate api Policy scoped to extension, discloses data collection, retention, and third-party sharing.
- function_constructor crx new Function() in scripts/zip.js enables dynamic code eval; likely from bundled zip library.
- dom_sink_innerhtml_userctrl crx innerHTML sink in content.js; no CSP to mitigate DOM-XSS risk.
- no_developer_name store developer_name field empty in listing; minor identity gap despite verified publisher badge.
- geo_diversity_3_countries api JS hosts span CA, DE, US — 3 countries, below +1.5 threshold of 4.
Permissions Breakdown
- activeTab low Grants access to the currently active tab only on user action.
- storage low Local data persistence; low risk in isolation.
- contextMenus low Adds right-click menu entries; standard UX pattern.
- declarativeNetRequestWithHostAccess high Can intercept/block/redirect network requests on all URLs.
- unlimitedStorage low Storage quota only; no data exfil risk on its own.
- <all_urls> (host_permissions) high Content scripts injected into every site; broad data access.
Pillar Scores
Permissions5.50
Reputation2.00
Network3.50
Webstore3.50
Maintenance0.00
Privacy0.00
Code Quality3.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 04:54
Listing SHA
782ea936019d…
Force block
— not fired
Score recovered
no
Elapsed
—