web translate - online translator
hnfabcchmopgohnhkcojhocneefbnffg
Risk Score
4.70
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's own account policy — not scoped to this extension; admits data collection and 3rd-party sharing (+10.0 privacy).
- Four moderate jQuery 2.2.4 CVEs (XSS) bundled; library far below fixed versions (3.4/3.5).
- Free-webmail developer (gmail) with no verified publisher status raises accountability concerns.
- Content scripts injected into *://*/* combined with tabs permission gives broad page-read capability across all sites.
- No CSP on MV3 extension; function_constructor (new Function()) detected in serviceWorker.js.
Evidence
- generic_privacy_policy store Privacy URL is Google Account policy; scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 privacy (D rule).
- cve_moderate_jquery crx jquery@2.2.4 has 4 moderate CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023, CVE-2015-9251); fixed in 3.5.0.
- free_webmail_dev store Developer email theodoreolszewski32@gmail.com; no verified publisher, no business domain.
- broad_host_access manifest host_permissions and content_scripts_matches both *://*/* — content injected on every page.
- function_constructor crx new Function() in javaScripts/serviceWorker.js; code_findings_raw authoritative.
- no_csp manifest content_security_policy is null; csp_present=false on MV3 extension.
- is_featured_by_google store Google Featured badge present; partially offsets reputation risk but developer accountability still low.
- maintenance_12mo store months_since_update=12; falls in 6-12 month band (+3.5 maintenance).
CVE Exposures (4)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@2.2.4 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@2.2.4 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@2.2.4 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@2.2.4 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- contextMenus low Adds right-click menu items; minimal risk.
- storage low Local preference storage; low risk.
- tabs medium Can read tab URLs and metadata across all tabs.
- *://*/* high Broad host access; content scripts inject into every page the user visits.
Pillar Scores
Permissions3.50
Reputation6.50
Network2.00
Webstore1.50
Maintenance3.50
Privacy10.00
Code Quality2.50
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 07:53
Listing SHA
12aff07453f9…
Force block
— not fired
Score recovered
no
Elapsed
—