Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

web translate - online translator

hnfabcchmopgohnhkcojhocneefbnffg
Risk Score
4.70
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category TranslationTool
Installs 30,000
Rating 4.3
Last updated 2025-08-29 (12 months ago)
Manifest version MV3
CSP present ❌ no
Developer theodoreolszewski32@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's own account policy — not scoped to this extension; admits data collection and 3rd-party sharing (+10.0 privacy).
  • Four moderate jQuery 2.2.4 CVEs (XSS) bundled; library far below fixed versions (3.4/3.5).
  • Free-webmail developer (gmail) with no verified publisher status raises accountability concerns.
  • Content scripts injected into *://*/* combined with tabs permission gives broad page-read capability across all sites.
  • No CSP on MV3 extension; function_constructor (new Function()) detected in serviceWorker.js.

Evidence

  • generic_privacy_policy store Privacy URL is Google Account policy; scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 privacy (D rule).
  • cve_moderate_jquery crx jquery@2.2.4 has 4 moderate CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023, CVE-2015-9251); fixed in 3.5.0.
  • free_webmail_dev store Developer email theodoreolszewski32@gmail.com; no verified publisher, no business domain.
  • broad_host_access manifest host_permissions and content_scripts_matches both *://*/* — content injected on every page.
  • function_constructor crx new Function() in javaScripts/serviceWorker.js; code_findings_raw authoritative.
  • no_csp manifest content_security_policy is null; csp_present=false on MV3 extension.
  • is_featured_by_google store Google Featured badge present; partially offsets reputation risk but developer accountability still low.
  • maintenance_12mo store months_since_update=12; falls in 6-12 month band (+3.5 maintenance).

CVE Exposures (4)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@2.2.4 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@2.2.4 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@2.2.4 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@2.2.4 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • contextMenus low Adds right-click menu items; minimal risk.
  • storage low Local preference storage; low risk.
  • tabs medium Can read tab URLs and metadata across all tabs.
  • *://*/* high Broad host access; content scripts inject into every page the user visits.

Pillar Scores

Permissions3.50
Reputation6.50
Network2.00
Webstore1.50
Maintenance3.50
Privacy10.00
Code Quality2.50
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 07:53
Listing SHA 12aff07453f9…
Force block — not fired
Score recovered no
Elapsed